D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.