D-Link behebt vier RCE-Fehler in DIR-846W-Routern nicht

Teilen:

D-Link is warning that four remote code execution (RCE) flaws impacting all hardware and firmware versions of its DIR-846W router will not be fixed as the products are no longer supported.

The four RCE flaws, three of which are rated critical and do not require authentication, were discovered by security researcher yali-1002, who released minimal details in their GitHub repository.

The researcher published the information on August 27, 2024, but has withheld the publication of proof-of-concept (PoC) exploits for now.

The flaws are summarized as follows:

  • CVE-2024-41622: Remote Command Execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1/ interface. (CVSS v3 score: 9.8 “critical”)
  • CVE-2024-44340: RCE vulnerability via the smartqos_express_devices and smartqos_normal_devices parameters in SetSmartQoSSettings (authenticated access requirement reduces the CVSS v3 score to 8.8 “high”).
  • CVE-2024-44341: RCE vulnerability via the lan(0)_dhcps_staticlist parameter, exploitable through a crafted POST request. (CVSS v3 score: 9.8 “critical”)
  • CVE-2024-44342: RCE vulnerability via the wl(0).(0)_ssid parameter. (CVSS v3 score: 9.8 “critical”)

Though D-Link acknowledged the security problems and their severity, it noted that they fall under its standard end-of-life/end-of-support policies, meaning there will be no security updates to address them.

“As a  general policy, when products reach EOS/EOL, they can no longer be supported, and all firmware development for these products cease,” reads D-Link’s announcement.

“D-Link strongly recommends that this product be retired and cautions that any further use of this product may be a risk to devices connected to it,” adds the vendor further down in the bulletin.

It is noted that DIR-846W routers were sold primarily outside the U.S., so the impact of the flaws should be minimal in the States, yet still significant globally. The model is still sold in some markets, including Latin America.

Though DIR-846 reached the end of support in 2020, over four years ago, many people only replace their routers once they face hardware problems or practical limitations, so a lot of people could still use the devices.

D-Link recommends that people still using the DIR-846 retire it immediately and replace it with a currently supported model.

If that is impossible, the hardware vendor recommends that users ensure the device runs the latest firmware, use strong passwords for the web admin portal, and enable WiFi encryption.

D-Link vulnerabilities are commonly exploited by malware botnets, such as Mirai and Moobot, to recruit devices into DDoS swarms. Threat actors have also recently exploited a D-Link DIR-859 router flaw to steal passwords and breach devices.

Therefore, securing the routers before proof-of-concept exploits are released and abused in attacks is vital.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:42 am, Juni 23, 2025
Wetter-Symbol 20°C
L: 19° | H: 21°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 46 %
Druck: 1014 mb
Wind: 17 mph W
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 42%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 21°°C 0 mm 0% 14 mph 54 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 24°°C 0 mm 0% 14 mph 80 % 1015 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 10 mph 88 % 1013 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 25°°C 0.35 mm 35% 16 mph 81 % 1017 mb 0 mm/h
Fr. Juni 27 10:00 pm
Wetter-Symbol
15° | 28°°C 0 mm 0% 15 mph 66 % 1020 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
20° | 21°°C 0 mm 0% 12 mph 46 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
20° | 21°°C 0 mm 0% 14 mph 42 % 1014 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
20° | 21°°C 0 mm 0% 14 mph 41 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 11 mph 54 % 1016 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 8 mph 69 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 8 mph 80 % 1014 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 11 mph 75 % 1014 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 69 % 1014 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€88,284.05
-1.01%
Ethereum(ETH)
€1,956.88
-0.41%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.74
-2.09%
Solana(SOL)
€116.45
0.40%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.132342
-1.99%
Shiba Inu(SHIB)
€0.000010
0.23%
Pepe(PEPE)
€0.000008
-2.51%
Peanut das Eichhörnchen(PNUT)
€0.218896
13.10%
Nach oben scrollen