First published: Thu Jan 19 2023(Updated: )
D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-859 A1 Firmware | =1.05 | |
Dlink Dir-859 A1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46476 refers to a command injection vulnerability discovered in D-Link DIR-859 A1 1.05 firmware.
The severity of CVE-2022-46476 is rated as critical with a CVSS score of 9.8.
CVE-2022-46476 allows attackers to execute arbitrary commands by exploiting the service= variable in the soapcgi_main function of D-Link DIR-859 A1 1.05 firmware.
Yes, D-Link DIR-859 A1 firmware version 1.05 is vulnerable to CVE-2022-46476.
To fix CVE-2022-46476, it is recommended to update the D-Link DIR-859 A1 firmware to a version that addresses the vulnerability.