CVE-2021-46441: OS Command Injection
In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-46441?
CVE-2021-46441 is a vulnerability in the "webupg" binary of D-Link DIR-825 G1 routers that allows attackers to execute arbitrary system commands after obtaining authorization.
How severe is CVE-2021-46441?
CVE-2021-46441 has a severity rating of 8.8 (critical).
What software is affected by CVE-2021-46441?
The D-Link DIR-825 G1 routers running Dlink Dir-825 Firmware are affected by CVE-2021-46441.
How can attackers exploit CVE-2021-46441?
Attackers can exploit CVE-2021-46441 by using the "cmd" parameter in the "webupg" binary to execute arbitrary system commands.
Where can I find more information about CVE-2021-46441?
You can find more information about CVE-2021-46441 at the following references: [Link 1](https://github.com/tgp-top/D-Link-DIR-825), [Link 2](https://www.dlink.com/en/security-bulletin/)