First published: Thu Feb 17 2022(Updated: )
A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin because backticks can be used for command injection when judging whether it is a reasonable domain name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-846 Firmware | =100a43 | |
Dlink Dir-846 | =a1 | |
Dlink Dir-846 Firmware | =100a53dla | |
Dlink Dir-846 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46314 is a Remote Command Execution (RCE) vulnerability in the HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 firmware.
CVE-2021-46314 has a severity rating of 9.8 (Critical).
D-Link Router DIR-846 firmware version 100a43 and 100a53dla are affected by CVE-2021-46314.
CVE-2021-46314 can be exploited through command injection using backticks in the domain name.
No, only D-Link Router DIR-846 firmware versions 100a43 and 100a53dla are vulnerable to CVE-2021-46314.