Share
## https://sploitus.com/exploit?id=55F1358B-0A7B-5456-9DB8-B00ED679850D
# CVE-2023-43284
DLink Model DIR-846 Authenticated Remote Code Execution.

This flaw abuse QoS POST parameter in the router to exploit an Authenticated Remote Code Execution. (Doesn't require QoS be enabled!)

```
  -h, --help        show this help message and exit
  -x , --command    Command to be executed (Default: id)
  -p , --password   Password from router.
  -i , --ip         IP from router. (Default: 192.168.0.1)
```
### Proof of Concept:
![Exploit](https://github.com/MateusTesser/CVE-2023-43284/blob/main/exploit.png?raw=true)

* Tested firmware version: 100A53DBR-Retail