3 results (0.008 seconds)

CVSS: 9.8EPSS: 1%CPEs: 2EXPL: 1

D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php. Los dispositivos D-Link DIR-846 con firmware 100A35 permiten a atacantes remotos ejecutar código arbitrario como root a través de HNAP1/control/SetGuestWLanSettings.php. • https://github.com/dahua966/Routers-vuls/blob/master/DIR-846/GuestWLanSetting_RCE.md https://www.dlink.com/en/security-bulletin •

CVSS: 10.0EPSS: 5%CPEs: 2EXPL: 1

D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetMasterWLanSettings with shell metacharacters to /squashfs-root/www/HNAP1/control/SetMasterWLanSettings.php. Los dispositivos D-Link DIR-846 con versión de firmware 100A35 , permiten a atacantes remotos ejecutar comandos arbitrarios del sistema operativo como root mediante el aprovechamiento del acceso de administrador y enviando una petición /HNAP1/ de la función SetMasterWLanSettings con metacaracteres de shell en archivo /squashfs-root/www/HNAP1/control/SetMasterWLanSettings.php. • https://github.com/dahua966/Routers-vuls/blob/master/DIR-846/vuls_info.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 10.0EPSS: 5%CPEs: 2EXPL: 1

D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetWizardConfig with shell metacharacters to /squashfs-root/www/HNAP1/control/SetWizardConfig.php. Los dispositivos D-Link DIR-846 con versión de firmware 100A35 , permiten a atacantes remotos ejecutar comandos arbitrarios del sistema operativo como root mediante el aprovechamiento del acceso de administrador y enviando un petición /HNAP1/ de la función SetWizardConfig con metacaracteres de shell en archivo /squashfs-root/www/HNAP1/control/SetWizardConfig.php. • https://github.com/dahua966/Routers-vuls/blob/master/DIR-846/vuls_info.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •