CVE-2021-46233: Command Injection
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function mspinfo.htm. This vulnerability allows attackers to execute arbitrary commands via the cmd parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46233?
CVE-2021-46233 is classified as a critical command injection vulnerability that can allow attackers to execute arbitrary commands.
How do I fix CVE-2021-46233?
To fix CVE-2021-46233, update the D-Link DI-7200GV2 to the latest firmware version beyond 21.04.09E1.
Which D-Link models are affected by CVE-2021-46233?
CVE-2021-46233 specifically affects the D-Link DI-7200GV2 devices running firmware version 21.04.09E1 or lower.
What impact can CVE-2021-46233 have on my D-Link device?
If exploited, CVE-2021-46233 can allow attackers to execute arbitrary commands, potentially compromising device security and network integrity.
Is there a way to mitigate CVE-2021-46233 if I can't update my firmware?
If a firmware update is not possible, mitigate CVE-2021-46233 by limiting network access to the device and monitoring for suspicious activity.