CVE-2021-46314: OS Command Injection
A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1FW100A43.bin and DIR846enFW100A53DLA-Retail.bin because backticks can be used for command injection when judging whether it is a reasonable domain name.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-46314?
CVE-2021-46314 is a Remote Command Execution (RCE) vulnerability in the HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 firmware.
What is the severity of CVE-2021-46314?
CVE-2021-46314 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2021-46314?
D-Link Router DIR-846 firmware version 100a43 and 100a53dla are affected by CVE-2021-46314.
How can CVE-2021-46314 be exploited?
CVE-2021-46314 can be exploited through command injection using backticks in the domain name.
Are all versions of D-Link Router DIR-846 vulnerable to CVE-2021-46314?
No, only D-Link Router DIR-846 firmware versions 100a43 and 100a53dla are vulnerable to CVE-2021-46314.