CVE-2021-46232: Command Injection
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function versionupgrade.asp. This vulnerability allows attackers to execute arbitrary commands via the path parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46232?
CVE-2021-46232 is considered a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2021-46232?
To remediate CVE-2021-46232, upgrade the D-Link DI-7200GV2 device firmware to version 21.04.09E1 or later.
What type of vulnerability is CVE-2021-46232?
CVE-2021-46232 is classified as a command injection vulnerability affecting the version_upgrade.asp function.
Which devices are affected by CVE-2021-46232?
CVE-2021-46232 affects the D-Link DI-7200GV2 devices running firmware versions up to and including 21.04.09E1.
What can attackers do with CVE-2021-46232?
Attackers exploiting CVE-2021-46232 can execute arbitrary commands on the vulnerable D-Link device.