CVE-2021-46441

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
27/04/2022
Last modified:
06/05/2022

Description

In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dir-825_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-825:g1:*:*:*:*:*:*:*