CVE-2022-46552 is a remote command execution (RCE) vulnerability affecting D-Link DIR-846 routers running Firmware FW100A53DBR. This high-severity flaw, with a CVSS score of 8.8, allows an authenticated attacker to execute arbitrary commands by sending a crafted POST request to the lan(0)_dhcps_staticlist parameter. While not currently listed in CISA's KEV catalog, public exploit code is available on ExploitDB, indicating a potential for exploitation. Despite the availability of exploit code, there is currently no evidence of active exploitation, nor significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
100a53dbrCPE matchmatch criteria | cpe:2.3:o:dlink:dir-846_firmware:100a53dbr:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.