First published: Fri Dec 23 2022(Updated: )
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-846 Firmware | =100a43 | |
Dlink Dir-846 | =a1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46641 is a command injection vulnerability found in D-Link DIR-846 A1_FW100A43 firmware.
CVE-2022-46641 has a severity rating of 9.9 (critical).
CVE-2022-46641 allows command injection via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function.
Yes, D-Link DIR-846 A1_FW100A43 firmware is affected by CVE-2022-46641.
To fix CVE-2022-46641, update to a fixed version provided by D-Link as soon as it becomes available.