CVE-2021-46319 is a critical Remote Code Execution (RCE) vulnerability affecting D-Link DIR-846 routers running specific firmware versions (DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin). This flaw, an incomplete patch for CVE-2019-17509, allows unauthenticated attackers to execute arbitrary commands by injecting shell metacharacters like backticks or line breaks into the ssid0 or ssid1 parameters. With a CVSS score of 9.8 (Critical), it poses a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, its high EPSS score indicates a significant probability of future exploitation, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
100a43CPE matchmatch criteria | cpe:2.3:o:dlink:dir-846_firmware:100a43:*:*:*:*:*:*:* | ||
100a53dlaCPE matchmatch criteria | cpe:2.3:o:dlink:dir-846_firmware:100a53dla:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.