Dlink Dir-846W Firmware vulnerabilities

4 known vulnerabilities affecting dlink/dir-846w_firmware.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1

Vulnerabilities

Page 1 of 1
CVE-2024-44341CRITICALCVSS 9.8vfw100a432024-08-27
CVE-2024-44341 [CRITICAL] CWE-78 CVE-2024-44341: D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.
nvd
CVE-2024-44342CRITICALCVSS 9.8vfw100a432024-08-27
CVE-2024-44342 [CRITICAL] CWE-78 CVE-2024-44342: D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.
nvd
CVE-2024-41622CRITICALCVSS 9.8vfw100a432024-08-27
CVE-2024-41622 [CRITICAL] CWE-78 CVE-2024-41622: D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.
nvd
CVE-2024-44340HIGHCVSS 8.8vfw100a432024-08-27
CVE-2024-44340 [HIGH] CWE-78 CVE-2024-44340: D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.
nvd