CVE-2021-46231: Command Injection
Published Feb 4, 2022
·Updated
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrdopt.asp. This vulnerability allows attackers to execute arbitrary commands via the urlen parameter.
Affected Software
2 affected components
Dlink Di-7200gv2 Firmware<=21.04.09e1
Dlink Di-7200gv2
Event History
Feb 4, 2022
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-46231?
CVE-2021-46231 is classified as a high severity vulnerability due to its ability to allow command injection.
2
How do I fix CVE-2021-46231?
To fix CVE-2021-46231, you should update the D-Link DI-7200GV2 firmware to version 21.04.09E1 or later.
3
What type of vulnerability is CVE-2021-46231?
CVE-2021-46231 is a command injection vulnerability affecting the urlrd_opt.asp function.
4
Which devices are affected by CVE-2021-46231?
CVE-2021-46231 affects D-Link DI-7200GV2 devices running firmware version 21.04.09E1 or earlier.
5
Can CVE-2021-46231 be exploited remotely?
Yes, CVE-2021-46231 can be exploited remotely by an attacker sending crafted requests to the vulnerable device.