CVE-2021-46319
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
17/02/2022
Last modified:
25/02/2022
Description
Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicious users can use this vulnerability to use "\ " or backticks to bypass the shell metacharacters in the ssid0 or ssid1 parameters to execute arbitrary commands.This vulnerability is due to the fact that CVE-2019-17509 is not fully patched and can be bypassed by using line breaks or backticks on its basis.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dlink:dir-846_firmware:100a43:*:*:*:*:*:*:* | ||
| cpe:2.3:h:dlink:dir-846:a1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:dlink:dir-846_firmware:100a53dla:*:*:*:*:*:*:* | ||
| cpe:2.3:h:dlink:dir-846:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



