First published: Fri Apr 02 2021(Updated: )
HNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to execute arbitrary commands via shell metacharacters in the ssid0 or ssid1 parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-846 Firmware | =a1_100.26 | |
Dlink Dir-846 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27600 is a vulnerability in D-Link Router DIR-846 firmware that allows remote attackers to execute arbitrary commands via shell metacharacters in the ssid0 or ssid1 parameter.
CVE-2020-27600 has a severity level of 9.8 (Critical).
Remote attackers can exploit CVE-2020-27600 by injecting shell metacharacters in the ssid0 or ssid1 parameter to execute arbitrary commands.
The vulnerability affects D-Link Router DIR-846 firmware version A1_100.26.
To fix CVE-2020-27600, users should update their D-Link Router DIR-846 firmware to a non-vulnerable version as recommended by D-Link.