vendor:
DIR-846
by:
Françoa Taffarel
8.8
CVSS
HIGH
Remote Command Execution (RCE)
78
CWE
Product Name: DIR-846
Affected Version From: DIR846enFW100A53DBR-Retail
Affected Version To: DIR846enFW100A53DBR-Retail
Patch Exists: YES
Related CWE: CVE-2022-46552
CPE: h:d-link:dir-846
Platforms Tested: D-LINK DIR-846
2023
D-Link DIR-846 – Remote Command Execution (RCE) vulnerability
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.
Mitigation:
The vendor has released a patch to address this vulnerability.