CVE-2020-21016: Code Injection
Published Oct 31, 2022
·Updated
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.
Affected Software
4 affected components
Dlink Dir-846 Firmware=100a35
Dlink Dir-846
All of the following
Dlink Dir-846 Firmware=100a35
Dlink Dir-846
Event History
Oct 31, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-21016?
CVE-2020-21016 is a vulnerability that allows remote attackers to execute arbitrary code as root on D-Link DIR-846 devices with firmware 100A35.
2
How severe is CVE-2020-21016?
CVE-2020-21016 has a severity rating of 9.8, which is classified as critical.
3
Which devices are affected by CVE-2020-21016?
D-Link DIR-846 devices with firmware version 100A35 are affected by CVE-2020-21016.
4
How can remote attackers exploit CVE-2020-21016?
Remote attackers can exploit CVE-2020-21016 by sending malicious requests to the HNAP1/control/SetGuestWLanSettings.php page.
5
Are there any references for CVE-2020-21016?
Yes, here are some references for CVE-2020-21016: [1] [2]