10

CVE-2018-19300

Exploit

On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
D-linkDap-1530 Firmware Version <= 1.05
   DlinkDap-1530 Version-
D-linkDap-1610 Firmware Version <= 1.05
   DlinkDap-1610 Version-
DlinkDwr-111 Firmware Version <= 1.01
   DlinkDwr-111 Version-
D-linkDwr-116 Firmware Version1.06 Updateb1
   DlinkDwr-116 Version-
D-linkDwr-116 Firmware Version1.06 Updateb2
   DlinkDwr-116 Version-
DlinkDwr-116 Firmware Version <= 1.05
   DlinkDwr-116 Version-
DlinkDwr-512 Firmware Version <= 2.02
   DlinkDwr-512 Version-
D-linkDwr-711 Firmware Version <= 1.11
   DlinkDwr-711 Version-
DlinkDwr-712 Firmware Version <= 2.02
   DlinkDwr-712 Version-
DlinkDwr-921 Firmware Version <= 1.02
   DlinkDwr-921 Version-
DlinkDwr-921 Firmware Version <= 2.02
   DlinkDwr-921 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 20.75% 0.954
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.