CVE-2020-21016
https://notcve.org/view.php?id=CVE-2020-21016
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php. Los dispositivos D-Link DIR-846 con firmware 100A35 permiten a atacantes remotos ejecutar código arbitrario como root a través de HNAP1/control/SetGuestWLanSettings.php. • https://github.com/dahua966/Routers-vuls/blob/master/DIR-846/GuestWLanSetting_RCE.md https://www.dlink.com/en/security-bulletin •
CVE-2019-17509
https://notcve.org/view.php?id=CVE-2019-17509
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetMasterWLanSettings with shell metacharacters to /squashfs-root/www/HNAP1/control/SetMasterWLanSettings.php. Los dispositivos D-Link DIR-846 con versión de firmware 100A35 , permiten a atacantes remotos ejecutar comandos arbitrarios del sistema operativo como root mediante el aprovechamiento del acceso de administrador y enviando una petición /HNAP1/ de la función SetMasterWLanSettings con metacaracteres de shell en archivo /squashfs-root/www/HNAP1/control/SetMasterWLanSettings.php. • https://github.com/dahua966/Routers-vuls/blob/master/DIR-846/vuls_info.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2019-17510
https://notcve.org/view.php?id=CVE-2019-17510
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetWizardConfig with shell metacharacters to /squashfs-root/www/HNAP1/control/SetWizardConfig.php. Los dispositivos D-Link DIR-846 con versión de firmware 100A35 , permiten a atacantes remotos ejecutar comandos arbitrarios del sistema operativo como root mediante el aprovechamiento del acceso de administrador y enviando un petición /HNAP1/ de la función SetWizardConfig con metacaracteres de shell en archivo /squashfs-root/www/HNAP1/control/SetWizardConfig.php. • https://github.com/dahua966/Routers-vuls/blob/master/DIR-846/vuls_info.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •