CVE-2021-46455
https://notcve.org/view.php?id=CVE-2021-46455
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStationSettings. This vulnerability allows attackers to execute arbitrary commands via the station_access_enable parameter. Se ha detectado que el dispositivo D-Link DIR-823-Pro versión v1.0.2, contiene una vulnerabilidad de inyección de comandos en la función SetStationSettings. Esta vulnerabilidad permite a atacantes ejecutar comandos arbitrarios por medio del parámetro station_access_enable • https://github.com/pjqwudi/my_vuln/blob/main/D-link/vuln_22/22.md https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10285 https://www.dlink.com/en/security-bulletin • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2021-46457
https://notcve.org/view.php?id=CVE-2021-46457
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgSambaUserSettings. This vulnerability allows attackers to execute arbitrary commands via the samba_name parameter. Se ha detectado que el dispositivo D-Link DIR-823-Pro versión v1.0.2, contiene una vulnerabilidad de inyección de comandos en la función ChgSambaUserSettings. Esta vulnerabilidad permite a atacantes ejecutar comandos arbitrarios por medio del parámetro samba_name • https://github.com/pjqwudi/my_vuln/blob/main/D-link/vuln_23/23.md https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10285 https://www.dlink.com/en/security-bulletin • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •