CVE-2021-46231
https://notcve.org/view.php?id=CVE-2021-46231
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability allows attackers to execute arbitrary commands via the url_en parameter. Se ha detectado que el dispositivo D-Link DI-7200GV2.E1 versión v21.04.09E1, contiene una vulnerabilidad de inyección de comandos en la función urlrd_opt.asp. Esta vulnerabilidad permite a atacantes ejecutar comandos arbitrarios por medio del parámetro url_en • https://github.com/pjqwudi/my_vuln/blob/main/D-link/vuln_5/5.md https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10284 https://www.dlink.com/en/security-bulletin • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2021-46232
https://notcve.org/view.php?id=CVE-2021-46232
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function version_upgrade.asp. This vulnerability allows attackers to execute arbitrary commands via the path parameter. Se ha detectado que el dispositivo D-Link DI-7200GV2.E1 versión v21.04.09E1, contiene una vulnerabilidad de inyección de comandos en la función version_upgrade.asp. Esta vulnerabilidad permite a atacantes ejecutar comandos arbitrarios por medio del parámetro path • https://github.com/pjqwudi/my_vuln/blob/main/D-link/vuln_8/8.md https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10284 https://www.dlink.com/en/security-bulletin • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2021-46233
https://notcve.org/view.php?id=CVE-2021-46233
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_info.htm. This vulnerability allows attackers to execute arbitrary commands via the cmd parameter. Se ha detectado que el dispositivo D-Link DI-7200GV2.E1 versión v21.04.09E1 contiene una vulnerabilidad de inyección de comandos en la función msp_info.htm. Esta vulnerabilidad permite a atacantes ejecutar comandos arbitrarios por medio del parámetro cmd • https://github.com/pjqwudi/my_vuln/blob/main/D-link/vuln_12/12.md https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10284 https://www.dlink.com/en/security-bulletin • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •