CVE-2022-46552: OS Command Injection
Published Feb 2, 2023
·Updated
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)dhcpsstaticlist parameter. This vulnerability is exploited via a crafted POST request.
Affected Software
4 affected components
Dlink Dir-846 Firmware=100a53dbr
Dlink Dir-846
All of the following
Dlink Dir-846 Firmware=100a53dbr
Dlink Dir-846
Event History
Feb 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-46552?
CVE-2022-46552 is a remote command execution (RCE) vulnerability found in D-Link DIR-846 Firmware FW100A53DBR.
2
How does CVE-2022-46552 impact D-Link DIR-846 Firmware FW100A53DBR?
CVE-2022-46552 allows remote attackers to execute arbitrary commands on the affected device.
3
What is the severity of CVE-2022-46552?
CVE-2022-46552 has a severity rating of 8.8 (high).
4
How can CVE-2022-46552 be exploited?
CVE-2022-46552 is exploited through a crafted POST request targeting the lan(0)_dhcps_staticlist parameter.
5
How can I mitigate the risk of CVE-2022-46552?
To mitigate the risk of CVE-2022-46552, users should update to a patched version of D-Link DIR-846 Firmware FW100A53DBR provided by the vendor.