Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicious users can use this vulnerability to use "\ " or backticks to bypass the shell metacharacters in the ssid0 or ssid1 parameters to execute arbitrary commands.This vulnerability is due to the fact that CVE-2019-17509 is not fully patched and can be bypassed by using line breaks or backticks on its basis.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
D-Link DIR-846 安全漏洞
Vulnerability Description
D-Link DIR-846是中国台湾友讯(D-Link)公司的一款无线路由器。 D-Link DIR-846 设备中存在操作系统命令注入漏洞,该漏洞源于产品未对ssid0 和 ssid1参数中的\和反引号进行有效过滤。攻击者可通过该漏洞执行代码。
CVSS Information
N/A
Vulnerability Type
N/A