In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices. In the SetRouterSettings.php source code, the RemotePort parameter is saved in the $path_inf_wan1."/web" internal configuration memory without any regex checking. And in the IPTWAN_build_command function of the iptwan.php source code, the data in $path_inf_wan1."/web" is used with the iptables command without any regex checking. A vulnerable /HNAP1/SetRouterSettings XML message could have shell metacharacters in the RemotePort element such as the `telnetd` string.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 818lw
HWDlinkall versionsDlink Dir 822
HWDlinkall versionsD Link Dir 818lw Firmware
OSD-Link2.05.b03D Link Dir 822 Firmware
OSD-Link202krb06
Related vulnerabilities
D-Link DIR-859: RCE jako root przez UPnP bez uwierzytelnienia
D-Link DIR-822+: Login bypass w interfejsie HNAP1 — puste hasło admina
Command injection w D-Link DIR-822+ — zdalne wykonanie poleceń
Buffer overflow w D-Link DIR-822 przez protokół HNAP (SetClientInfo)
Command injection w D-Link DIR-822/860L/868L/880L/890L przez HNAP1