Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-43284 PoC — D-Link DIR-846 安全漏洞

Source
Associated Vulnerability
Title:D-Link DIR-846 安全漏洞 (CVE-2023-43284)
Description:D-Link DIR-846是中国友讯(D-Link)公司的一款无线路由器。 D-Link DIR-846 固件版本 100A53DBR-Retail存在安全漏洞,该漏洞源于允许远程攻击者执行任意代码。
Description
DLink DIR-846 Authenticated Remote Code Execution
Readme
# CVE-2023-43284
DLink Model DIR-846 Authenticated Remote Code Execution.

This flaw abuse QoS POST parameter in the router to exploit an Authenticated Remote Code Execution. (Doesn't require QoS be enabled!)

```
  -h, --help        show this help message and exit
  -x , --command    Command to be executed (Default: id)
  -p , --password   Password from router.
  -i , --ip         IP from router. (Default: 192.168.0.1)
```
### Proof of Concept:
![Exploit](https://github.com/MateusTesser/CVE-2023-43284/blob/main/exploit.png?raw=true)

* Tested firmware version: 100A53DBR-Retail 
File Snapshot

[4.0K] /data/pocs/d54062ba248e6ab5be840e7c9620d20e42d0fc81 ├── [5.8K] dlink.py ├── [ 20K] exploit.png └── [ 586] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.