CVE-2021-46315

CRITICAL

D-Link DIR-846 Firmware - Remote Command Execution via HNAP1 SetWizardConfig SSID Parameter Injection

Title source: llm
STIX 2.1

Description

Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicoius users can use this vulnerability to use "\ " or backticks in the shell metacharacters in the ssid0 or ssid1 parameters to cause arbitrary command execution. Since CVE-2019-17510 vulnerability has not been patched and improved www/hnap1/control/setwizardconfig.php, can also use line breaks and backquotes to bypass.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.3204
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
dlink/dir-846_firmware 100a43
dlink/dir-846_firmware 100a53dla
Published Feb 17, 2022
Tracked Since Feb 18, 2026