CVE-2022-46641: Command Injection
Published Dec 23, 2022
·Updated
D-Link DIR-846 A1FW100A43 was discovered to contain a command injection vulnerability via the lan(0)dhcpsstaticlist parameter in the SetIpMacBindSettings function.
Affected Software
4 affected components
Dlink Dir-846 Firmware=100a43
Dlink Dir-846=a1
All of the following
Dlink Dir-846 Firmware=100a43
Dlink Dir-846=a1
Event History
Dec 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-46641?
CVE-2022-46641 is a command injection vulnerability found in D-Link DIR-846 A1_FW100A43 firmware.
2
How severe is CVE-2022-46641?
CVE-2022-46641 has a severity rating of 9.9 (critical).
3
How does CVE-2022-46641 affect D-Link DIR-846 A1_FW100A43 firmware?
CVE-2022-46641 allows command injection via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function.
4
Is D-Link DIR-846 A1_FW100A43 firmware affected?
Yes, D-Link DIR-846 A1_FW100A43 firmware is affected by CVE-2022-46641.
5
How can I fix CVE-2022-46641?
To fix CVE-2022-46641, update to a fixed version provided by D-Link as soon as it becomes available.