CRITICAL
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetWizardConfig with shell metacharacters to /squashfs-root/www/HNAP1/control/SetWizardConfig.php
Published Oct 11, 2019
9.8
CRITICALCVSS 3.1
EPSS 3.56%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.