← Vulnerability feed

Vulnerability record · CVE-2021-46378 · published 4 March 2022

CVE-2021-46378: Dlink dir-850l firmware vulnerability

Dlink · Dir 850l Firmware

DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.

7.5 CVSS 3.1 High EPSS 32% · top 1.8% CWE-425 · CWE-425
7.5CVSS 3.1 base score, v2 5.0
32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-46378 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-49004Dlink dir-850l firmware code injection vulnerabilityAn issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter.EPSS 1.9%9.8CVE-2018-20675Dlink dir-822 firmware improper authentication vulnerabilityD-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-8…EPSS 1.8%9.8CVE-2016-6563D-Link DIR routers stack buffer overflow via HNAP SOAP loginMalformed SOAP messages sent to the HNAP Login action overflow a stack buffer in several D-Link DIR router models. The vulnerable XML fields are Acti…EPSS 80%analysed9.8CVE-2018-9032Dlink dir-850l firmware improper authentication vulnerabilityAn authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version…EPSS 28%9.8CVE-2017-14417Dlink dir-850l firmware missing authentication for critical function vulnerabilityregister_send.php on D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices does not require authentication, which can result in unintende…EPSS 1.3%9.8CVE-2017-14421Dlink dir-850l firmware hard-coded credentials vulnerabilityD-Link DIR-850L REV. B (with firmware through FW208WWb02) devices have a hardcoded password of wrgac25_dlink.2013gui_dir850l for the Alphanetworks ac…EPSS 2.3%9.8CVE-2017-14429Dlink dir-850l firmware os command injection vulnerabilityThe DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows …EPSS 4.9%8.8CVE-2018-20674Dlink dir-822 firmware vulnerabilityD-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-8…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2021-46378), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.