Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-19300


On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.


Published

2019-04-11T16:29:00.620

Last Modified

2024-11-21T03:57:42.013

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System d-link dap-1530_firmware ≤ 1.05 Yes
Hardware dlink dap-1530 - No
Operating System d-link dap-1610_firmware ≤ 1.05 Yes
Hardware dlink dap-1610 - No
Operating System dlink dwr-111_firmware ≤ 1.01 Yes
Hardware dlink dwr-111 - No
Operating System d-link dwr-116_firmware 1.06 Yes
Operating System d-link dwr-116_firmware 1.06 Yes
Operating System dlink dwr-116_firmware ≤ 1.05 Yes
Hardware dlink dwr-116 - No
Operating System dlink dwr-512_firmware ≤ 2.02 Yes
Hardware dlink dwr-512 - No
Operating System d-link dwr-711_firmware ≤ 1.11 Yes
Hardware dlink dwr-711 - No
Operating System dlink dwr-712_firmware ≤ 2.02 Yes
Hardware dlink dwr-712 - No
Operating System dlink dwr-921_firmware ≤ 1.02 Yes
Hardware dlink dwr-921 - No
Operating System dlink dwr-921_firmware ≤ 2.02 Yes
Hardware dlink dwr-921 - No

References