CVE Vulnerabilities

CVE-2021-46442

Published: Apr 27, 2022 | Modified: May 07, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In the webupg binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters autoupgrade.asp, and perform functions such as downloading configuration files and updating firmware without authorization.

Affected Software

Name Vendor Start Version End Version
Dir-825_firmware Dlink - (including) - (including)

References