CVE-2022-46476: OS Command Injection
Published Jan 19, 2023
·Updated
D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgimain function.
Affected Software
4 affected components
Dlink Dir-859 A1 Firmware=1.05
Dlink Dir-859 A1
All of the following
Dlink Dir-859 A1 Firmware=1.05
Dlink Dir-859 A1
Event History
Jan 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-46476?
CVE-2022-46476 refers to a command injection vulnerability discovered in D-Link DIR-859 A1 1.05 firmware.
2
What is the severity of CVE-2022-46476?
The severity of CVE-2022-46476 is rated as critical with a CVSS score of 9.8.
3
How does CVE-2022-46476 affect D-Link DIR-859 A1 firmware?
CVE-2022-46476 allows attackers to execute arbitrary commands by exploiting the service= variable in the soapcgi_main function of D-Link DIR-859 A1 1.05 firmware.
4
Is D-Link DIR-859 A1 vulnerable?
Yes, D-Link DIR-859 A1 firmware version 1.05 is vulnerable to CVE-2022-46476.
5
How can I fix CVE-2022-46476 in D-Link DIR-859 A1 firmware?
To fix CVE-2022-46476, it is recommended to update the D-Link DIR-859 A1 firmware to a version that addresses the vulnerability.