Command Injection Vulnerability in D-Link DIR-823-Pro Devices
CVE-2021-46456
9.8CRITICAL
What is CVE-2021-46456?
A command injection vulnerability exists in the D-Link DIR-823-Pro firmware v1.0.2, specifically in the SetWLanACLSettings function. This flaw allows unauthorized users to execute arbitrary commands by manipulating the wl(0).(0)_maclist parameter. This security risk may lead to compromised device functionality, making it imperative for users to apply security updates or patches provided by D-Link to mitigate potential threats.