cbcvebase.
CVE-2024-44341
published 2024-08-27

CVE-2024-44341: D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This…

PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.83%
76.4th percentile
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

Affected

1 ranges
VendorProductVersion rangeFixed in
dlinkdir-846w_firmware

Detection & IOCsextracted from sources · hover to see the quote

url/HNAP1/
  • CVE-2024-44341 is exploited via a crafted POST request targeting the lan(0)_dhcps_staticlist parameter on D-Link DIR-846W A1 FW100A43 routers. Monitor for POST requests containing this parameter.
  • Related CVE-2024-41622 targets the /HNAP1/ interface via the tomography_ping_address parameter; monitor POST requests to /HNAP1/ on DIR-846W devices for anomalous parameter values.
  • ·CVE-2024-44341 affects D-Link DIR-846W A1 firmware version FW100A43 specifically. No patch will be issued as the device is end-of-life/end-of-support (EOS/EOL since 2020).
  • ·The vulnerability requires no authentication (CVSS v3: 9.8 critical), making it remotely exploitable without credentials via a crafted POST request.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.