On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can occur in the soap.cgi service of the cgibin binary via an "&&" substring in the service parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-6530.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 818lw
HWDlinkall versionsDlink Dir 818lw Firmware
OSDlink2.05.b03Dlink Dir 860l
HWDlinkall versionsDlink Dir 860l Firmware
OSDlink2.03.b03
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
Related vulnerabilities
CVE-2018-6530CRITICAL9.8⚠ KEVPL ✓same product
D-Link DIR-860L/865L/868L/880L — command injection przez soap.cgi
CVE-2024-42812CRITICAL9.8PL ✓same product
Buffer overflow w D-Link DIR-860L v2.03 — brak weryfikacji długości pola SID
CVE-2024-41611CRITICAL9.8PL ✓same product
D-Link DIR-860L: hardcoded credentials w usłudze Telnet umożliwiają RCE
CVE-2018-19986CRITICAL9.8PL ✓same product
Command injection w D-Link DIR-818LW i DIR-822 przez parametr RemotePort
CVE-2018-19987CRITICAL9.8PL ✓same product
Command injection w D-Link DIR-822/860L/868L/880L/890L przez HNAP1