CVE-2022-46642: Command Injection
Published Dec 23, 2022
·Updated
D-Link DIR-846 A1FW100A43 was discovered to contain a command injection vulnerability via the autoupgradehour parameter in the SetAutoUpgradeInfo function.
Affected Software
4 affected components
Dlink Dir-846 Firmware=100a43
Dlink Dir-846=a1
All of the following
Dlink Dir-846 Firmware=100a43
Dlink Dir-846=a1
Event History
Dec 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the D-Link DIR-846 A1_FW100A43 vulnerability?
The vulnerability ID is CVE-2022-46642.
2
What is the severity of the D-Link DIR-846 A1_FW100A43 vulnerability?
The severity of the vulnerability is critical with a score of 9.9.
3
What software is affected by the D-Link DIR-846 A1_FW100A43 vulnerability?
The D-Link DIR-846 Firmware version 100a43 is affected by this vulnerability.
4
How can the D-Link DIR-846 A1_FW100A43 vulnerability be exploited?
The vulnerability can be exploited through the auto_upgrade_hour parameter in the SetAutoUpgradeInfo function.
5
Are there any references available for the D-Link DIR-846 A1_FW100A43 vulnerability?
Yes, you can refer to the following links for more information: [GitHub](https://github.com/CyberUnicornIoT/IoTvuln/blob/main/d-link/dir-846/D-Link%20dir-846%20SetAutoUpgradeInfo%20command%20injection%20vulnerability.md) and [D-Link Security Bulletin](https://www.dlink.com/en/security-bulletin/).