PT-2022-6264 · D Link · D-Link Dir-846

Françoa Taffarel Rosário Corrêa

+2

·

Published

2022-11-30

·

Updated

2023-04-06

·

CVE-2022-46552

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-846 Firmware FW100A53DBR
Description The issue is related to a remote command execution vulnerability via the lan(0) dhcps staticlist parameter. This vulnerability can be exploited through a crafted POST request, allowing a remote attacker to execute arbitrary commands. The vulnerability is due to the lack of proper sanitization of special elements used in the operating system command when processing the lan(0) dhcps staticlist parameter.
Recommendations For D-Link DIR-846 Firmware FW100A53DBR, as a temporary workaround, consider disabling the lan(0) dhcps staticlist parameter until a patch is available. Restrict access to the vulnerable parameter to minimize the risk of exploitation. Avoid using the lan(0) dhcps staticlist parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00679
CVE-2022-46552

Affected Products

D-Link Dir-846