Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-10823


An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.


Published

2018-10-17T14:29:00.787

Last Modified

2024-11-21T03:42:05.663

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dwr-116_firmware ≤ 1.06 Yes
Hardware dlink dwr-116 - No
Operating System dlink dwr-512_firmware ≤ 2.02 Yes
Hardware dlink dwr-512 - No
Operating System dlink dwr-912_firmware ≤ 2.02 Yes
Hardware dlink dwr-921 - No
Operating System dlink dwr-111_firmware ≤ 1.01 Yes
Hardware dlink dwr-111 - No

References