MateusTesser / CVE-2023-43284

DLink DIR-846 Authenticated Remote Code Execution

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2023-43284

DLink Model DIR-846 Authenticated Remote Code Execution.

This flaw abuse QoS POST parameter in the router to exploit an Authenticated Remote Code Execution. (Doesn't require QoS be enabled!)

  -h, --help        show this help message and exit
  -x , --command    Command to be executed (Default: id)
  -p , --password   Password from router.
  -i , --ip         IP from router. (Default: 192.168.0.1)

Proof of Concept:

Exploit

  • Tested firmware version: 100A53DBR-Retail

About

DLink DIR-846 Authenticated Remote Code Execution


Languages

Language:Python 100.0%