← Vulnerability feed

Vulnerability record · CVE-2023-6580 · published 7 December 2023

CVE-2023-6580: Dlink dir-846 firmware deserialization of untrusted data vulnerability

Dlink · Dir 846 Firmware

A vulnerability, which was classified as critical, was found in D-Link DIR-846 FW100A53DBR. This affects an unknown part of the file /HNAP1/ of the component QoS POST Handler. The manipulation of the argument smartqos_express_devices/smartqos_normal_devices leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

8.8 CVSS 3.1 High EPSS 2.3% · top 16.9% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score, v2 9.0
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability, which was classified as critical, was found in D-Link DIR-846 FW100A53DBR. This affects an unknown part of the file /HNAP1/ of the component QoS POST Handler. The manipulation of the argument smartqos_express_devices/smartqos_normal_devices leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/c2dc/cve-reported/blob/main/CVE-2023-6580/CVE-2023-6580.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.247161 Permissions RequiredThird Party Advisory
https://vuldb.com/?id.247161 Third Party Advisory
https://github.com/c2dc/cve-reported/blob/main/CVE-2023-6580/CVE-2023-6580.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.247161 Permissions RequiredThird Party Advisory
https://vuldb.com/?id.247161 Third Party Advisory

Track CVE-2023-6580 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2022-46642Dlink dir-846 firmware command injection vulnerabilityD-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo …EPSS 3.1%9.9CVE-2022-46641Dlink dir-846 firmware command injection vulnerabilityD-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindS…EPSS 3.1%9.8CVE-2023-33735Dlink dir-846 firmware vulnerabilityD-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HN…EPSS 33%9.8CVE-2020-21016Dlink dir-846 firmware code injection vulnerabilityD-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.EPSS 2.2%9.8CVE-2021-46315Dlink dir-846 firmware os command injection vulnerabilityRemote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enF…EPSS 6.6%9.8CVE-2021-46319Dlink dir-846 firmware os command injection vulnerabilityRemote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicious users c…EPSS 6.6%9.8CVE-2021-46314Dlink dir-846 firmware os command injection vulnerabilityA Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bi…EPSS 33%9.8CVE-2020-27600Dlink dir-846 firmware os command injection vulnerabilityHNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to execute arbitrary commands via s…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2023-6580), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.