HNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to execute arbitrary commands via shell metacharacters in the ssid0 or ssid1 parameter.
References
Link | Resource |
---|---|
https://github.com/pwnninja/dlink/blob/main/DIR-846_SetMasterWLanSettingsCI.md | Exploit Third Party Advisory |
https://www.dlink.com | Vendor Advisory |
https://www.dlink.com/en/security-bulletin/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-04-02T20:11:40
Updated: 2021-04-02T20:11:40
Reserved: 2020-10-21T00:00:00
Link: CVE-2020-27600
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-04-02T21:15:13.560
Modified: 2021-04-09T13:32:43.603
Link: CVE-2020-27600
JSON object: View
Redhat Information
No data.
CWE