CVE-2024-41622
published 2024-08-27CVE-2024-41622: D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.03%
78.8th percentile
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-846w_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor POST requests to /HNAP1/ for the presence of the 'tomography_ping_address' parameter containing shell metacharacters or command injection payloads. ↗
- →Target device is D-Link DIR-846W A1 running firmware FW100A43; fingerprint HTTP responses or User-Agent/banner strings to identify exposed instances. ↗
- →This vulnerability requires no authentication (CVSS 9.8); treat any unauthenticated request to /HNAP1/ carrying tomography_ping_address as high-priority alert. ↗
- ·The DIR-846W is primarily sold outside the U.S. (notably Latin America), so exposure is globally distributed but limited in the U.S. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2024-08-27
Published