CVE-2021-46441
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
27/04/2022
Last modified:
06/05/2022
Description
In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dlink:dir-825_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:dlink:dir-825:g1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



