HIGH
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter
Published Feb 2, 2023
8.8
HIGHCVSS 3.1
EPSS 10.50%
Description
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.
Affected products
No data.
AND
- 100a53dbr
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://packetstormsecurity.com/files/171710/D-Link-DIR-846-Remote-Command-Execution.html
- https://cwe.mitre.org/data/definitions/78.html Third Party Advisory
- https://francoataffarel.medium.com/cve-2022-46552-d-link-dir-846-wireless-router-in-firmware-fw100a53dbr-retail-has-a-vulnerability-5b4ca1864c6e ExploitThird Party Advisory
- https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php Third Party Advisory
- https://github.com/c2dc/cve-reported/blob/main/CVE-2022-46552/CVE-2022-46552.md ExploitThird Party Advisory
- https://www.dlink.com/en/security-bulletin/ Vendor Advisory
- https://www.php.net/manual/en/ref.exec.php Not Applicable
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/171710/D-Link-DIR-846-Remote-Command-Execution.html | ||
| https://cwe.mitre.org/data/definitions/78.html | Third Party Advisory | |
| https://francoataffarel.medium.com/cve-2022-46552-d-link-dir-846-wireless-router-in-firmware-fw100a53dbr-retail-has-a-vulnerability-5b4ca1864c6e | ExploitThird Party Advisory | |
| https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php | Third Party Advisory | |
| https://github.com/c2dc/cve-reported/blob/main/CVE-2022-46552/CVE-2022-46552.md | ExploitThird Party Advisory | |
| https://www.dlink.com/en/security-bulletin/ | Vendor Advisory | |
| https://www.php.net/manual/en/ref.exec.php | Not Applicable |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 2, 2023
Updated Mar 27, 2025
Reserved Dec 5, 2022
Link CVE-2022-46552
CISA Vulnrichment
Updated Mar 27, 2025