PT-2022-1648 · D Link · D-Link Router Dir-846

Published

2022-02-17

·

Updated

2022-02-25

·

CVE-2021-46315

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link Router DIR-846 versions DIR846A1 FW100A43.bin through DIR846enFW100A53DLA-Retail.bin
Description A Remote Command Execution (RCE) issue exists due to insufficient argument validation in the SetWizardConfig.php script within the HNAP1/control directory. This allows malicious users to execute arbitrary commands by using shell metacharacters, such as backticks or line breaks, in the ssid0 or ssid1 parameters.
Recommendations For D-Link Router DIR-846 versions DIR846A1 FW100A43.bin through DIR846enFW100A53DLA-Retail.bin, consider disabling the SetWizardConfig.php script in the HNAP1/control directory until a patch is available to prevent exploitation. Restrict access to the ssid0 and ssid1 parameters in the affected API endpoint to minimize the risk of command execution. Avoid using the parameters ssid0 and ssid1 in the affected API endpoint until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00897
CVE-2021-46315

Affected Products

D-Link Router Dir-846