CVE-2024-44340 is a high-severity Remote Command Execution (RCE) vulnerability affecting D-Link DIR-846W A1 routers running firmware version FW100A43. This flaw allows authenticated attackers to execute arbitrary commands by manipulating the smartqos_express_devices and smartqos_normal_devices keys within the SetSmartQoSSettings function. With a CVSS score of 8.8, successful exploitation can lead to complete compromise of the device, including confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness of the issue. D-Link has stated they will not be patching this vulnerability as the product is discontinued.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
fw100a43CPE matchmatch criteria | cpe:2.3:o:dlink:dir-846w_firmware:fw100a43:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.