Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-6530


OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.


Published

2018-03-06T20:29:00.987

Last Modified

2025-04-03T20:28:21.333

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-78
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dir-860l_firmware ≤ a1_fw110b04 Yes
Hardware dlink dir-860l - No
Operating System dlink dir-865l_firmware ≤ reva_firmware_patch_1.08.b01 Yes
Hardware dlink dir-865l - No
Operating System dlink dir-868l_firmware ≤ a1_fw112b04 Yes
Hardware dlink dir-868l - No
Operating System dlink dir-880l_firmware ≤ reva_firmware_patch_1.08b04 Yes
Hardware dlink dir-880l - No

References