CVE-2021-46442: Critical severity d-link dir-825 firmware vulnerability
Published Apr 27, 2022
·Updated
In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization.
Affected Software
2 affected components
Dlink Dir-825 Firmware
Dlink DIR-825=g1
Event History
Apr 27, 2022
CVE Published
via MITRE·10:10 AM
Data Sourced
via MITRE·10:10 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-46442.
2
What is the severity of CVE-2021-46442?
The severity of CVE-2021-46442 is critical with a CVSS score of 9.8.
3
How does the vulnerability CVE-2021-46442 affect D-Link DIR-825 G1?
The vulnerability CVE-2021-46442 allows attackers to bypass authentication in the "webupg" binary of D-Link DIR-825 G1 and perform unauthorized actions such as downloading configuration files and updating firmware.
4
Is D-Link DIR-825 G1 firmware vulnerable to CVE-2021-46442?
Yes, D-Link DIR-825 G1 firmware is vulnerable to CVE-2021-46442.
5
How can I fix the vulnerability CVE-2021-46442?
To fix the vulnerability CVE-2021-46442, D-Link recommends updating the firmware to the latest version available.