CRITICAL🇵🇱 Wersja polska

CVE-2018-19986

CVSS 9.8v3.0pub. 2019-05-13upd. 2024-11-21

In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices. In the SetRouterSettings.php source code, the RemotePort parameter is saved in the $path_inf_wan1."/web" internal configuration memory without any regex checking. And in the IPTWAN_build_command function of the iptwan.php source code, the data in $path_inf_wan1."/web" is used with the iptables command without any regex checking. A vulnerable /HNAP1/SetRouterSettings XML message could have shell metacharacters in the RemotePort element such as the `telnetd` string.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dlink Dir 818lw

    HW
    Dlink
    all versions
  • Dlink Dir 822

    HW
    Dlink
    all versions
  • D Link Dir 818lw Firmware

    OS
    D-Link
    2.05.b03
  • D Link Dir 822 Firmware

    OS
    D-Link
    202krb06
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2019-17621CRITICAL9.8⚠ KEVPL ✓same product

D-Link DIR-859: RCE jako root przez UPnP bez uwierzytelnienia

CVE-2023-51987CRITICAL9.8PL ✓same product

D-Link DIR-822+: Login bypass w interfejsie HNAP1 — puste hasło admina

CVE-2023-51984CRITICAL9.8PL ✓same product

Command injection w D-Link DIR-822+ — zdalne wykonanie poleceń

CVE-2019-6258CRITICAL9.8PL ✓same product

Buffer overflow w D-Link DIR-822 przez protokół HNAP (SetClientInfo)

CVE-2018-19987CRITICAL9.8PL ✓same product

Command injection w D-Link DIR-822/860L/868L/880L/890L przez HNAP1