CVE-2022-46552
HIGHD-Link DIR-846 FW100A53DBR - Remote Command Execution via lan_dhcps_staticlist
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2022-46552. PoCs published by Françoa Taffarel.
AI-analyzed exploit summary This exploit demonstrates a remote command execution (RCE) vulnerability in D-Link DIR-846 firmware FW100A53DBR via the `lan(0)_dhcps_staticlist` parameter. The crafted POST request injects a command (`$(id>rce_confirmed)`) into the parameter, which is executed on the target device, confirming RCE by retrieving the output via a subsequent GET request.
Description
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.
Exploits (1)
This exploit demonstrates a remote command execution (RCE) vulnerability in D-Link DIR-846 firmware FW100A53DBR via the `lan(0)_dhcps_staticlist` parameter. The crafted POST request injects a command (`$(id>rce_confirmed)`) into the parameter, which is executed on the target device, confirming RCE by retrieving the output via a subsequent GET request.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H