Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2021-46379 — Open Redirect in Dlink Dir-850l Firmware

CWE-601 — Open Redirect6 documents6 sources
Severity
6.1MEDIUMNVD
EPSS
46.9%
top 2.32%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 4
Latest updateMay 11

Description

DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

â–¶NVDdlink/dir-850l_firmware1.08trb03

🔴Vulnerability Details

3
GHSA
GHSA-276x-qw7f-57vq: DLink DIR850 ET850-1↗2022-03-05
â–¶
CVEList
CVE-2021-46379: DLink DIR850 ET850-1↗2022-03-04
â–¶
VulnCheck
D-Link dir-850l_firmware URL Redirection to Untrusted Site ('Open Redirect')↗2021
â–¶

💥Exploits & PoCs

2
Exploit-DB
DLINK DIR850 - Open Redirect↗2022-05-11
â–¶
Nuclei
D-Link DIR850 ET850-1.08TRb03 - Open Redirect
â–¶
CVE-2021-46379 — Open Redirect in Dlink | cvebase