NA

CVE-2023-43284

Published: 05/10/2023 Updated: 22/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

D-Link Wireless MU-MIMO Gigabit AC1200 Router DIR-846 100A53DBR-Retail devices allow an authenticated remote malicious user to execute arbitrary code via an unspecified manipulation of the QoS POST parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dir-846_firmware 100a53dbr

Github Repositories

DLink DIR-846 Authenticated Remote Code Execution

CVE-2023-43284 DLink Model DIR-846 Authenticated Remote Code Execution This flaw abuse QoS POST parameter in the router to exploit an Authenticated Remote Code Execution (Doesn't require QoS be enabled!) -h, --help show this help message and exit -x , --command Command to be executed (Default: id) -p , --password Password from router -i , --ip