CVE-2021-46230: Command Injection
Published Feb 4, 2022
·Updated
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgradefilter. This vulnerability allows attackers to execute arbitrary commands via the path and time parameters.
Affected Software
2 affected components
Dlink Di-7200gv2 Firmware<=21.04.09e1
Dlink Di-7200gv2
Event History
Feb 4, 2022
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-46230?
CVE-2021-46230 has a high severity due to its potential for arbitrary command execution.
2
How do I fix CVE-2021-46230?
To fix CVE-2021-46230, upgrade to a firmware version later than 21.04.09E1 for the D-Link DI-7200GV2 device.
3
What devices are vulnerable to CVE-2021-46230?
CVE-2021-46230 specifically affects the D-Link DI-7200GV2 firmware version 21.04.09E1 and below.
4
Can CVE-2021-46230 be exploited remotely?
Yes, CVE-2021-46230 can be exploited remotely by attackers who know how to send crafted requests.
5
What functionalities are affected by CVE-2021-46230?
CVE-2021-46230 affects the upgrade_filter function, allowing command injection through path and time parameters.