CVE-2024-44341
published 2024-08-27CVE-2024-44341: D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.83%
76.4th percentile
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-846w_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-44341 is exploited via a crafted POST request targeting the lan(0)_dhcps_staticlist parameter on D-Link DIR-846W A1 FW100A43 routers. Monitor for POST requests containing this parameter. ↗
- →Related CVE-2024-41622 targets the /HNAP1/ interface via the tomography_ping_address parameter; monitor POST requests to /HNAP1/ on DIR-846W devices for anomalous parameter values. ↗
- ·CVE-2024-44341 affects D-Link DIR-846W A1 firmware version FW100A43 specifically. No patch will be issued as the device is end-of-life/end-of-support (EOS/EOL since 2020). ↗
- ·The vulnerability requires no authentication (CVSS v3: 9.8 critical), making it remotely exploitable without credentials via a crafted POST request. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2024-08-27
Published