D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.
https://github.com/n0wstr/IOTVuln/tree/main/DIR-822%2B/UploadFirmware
http://www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DIR-822%2B