peter bassill · operator
$ cve CVE-2018-10823 JSON

CVE-2018-10823 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 77.7% (pctl 100)

Patch early

A public exploit exists.

Description

An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS77.7% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2018-10-17
Last modified2026-06-17

Affected (8)

VendorProduct
dlinkdwr-111
dlinkdwr-111 firmware
dlinkdwr-116
dlinkdwr-116 firmware
dlinkdwr-512
dlinkdwr-512 firmware
dlinkdwr-912 firmware
dlinkdwr-921

Public exploits

SourceTitleDate
exploit-dbD-Link Routers - Command Injection2018-10-12

References

→ the Explorer  ·  watch your stack  ·  NVD