CRITICAL🇵🇱 Wersja polska

CVE-2021-46442

CVSS 9.8v3.1pub. 2022-04-27upd. 2024-11-21

In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dlink Dir 825

    HW
    Dlink
    g1
  • Dlink Dir 825 Firmware

    OS
    Dlink
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2020-29557CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w D-Link DIR-825 umożliwiający RCE bez uwierzytelnienia

CVE-2019-16920CRITICAL9.8⚠ KEVPL ✓same product

D-Link: Nieuwierzytelniony RCE przez command injection w PingTest CGI

CVE-2022-47035CRITICAL9.8PL ✓same product

Buffer Overflow w D-Link DIR-825 umożliwiający zdalne wykonanie kodu

CVE-2026-7068HIGH7.4same product

A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file s...

CVE-2026-7069HIGH7.3same product

A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping ...