A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin because backticks can be used for command injection when judging whether it is a reasonable domain name.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T05:02:11.058Z
Reserved: 2022-01-18T00:00:00
Link: CVE-2021-46314
No data.
Status : Modified
Published: 2022-02-17T21:15:07.787
Modified: 2024-11-21T06:33:52.127
Link: CVE-2021-46314
No data.
OpenCVE Enrichment
No data.
Weaknesses