CRITICAL🇵🇱 Wersja polska

CVE-2018-25120

CVSS 9.3v4.0pub. 2025-10-29upd. 2025-11-28

D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulnerability in the Mail Test functionality. The web maintenance script posts to the internal goForm endpoint '/goform/Mail_Test' and uses several form parameters directly in a call to a system email utility without proper input validation. An unauthenticated remote attacker can supply crafted form data that injects shell commands, resulting in execution as root on the device. NOTE: The DNS-343 product line has been declared end-of-life.

🤖 AI Analysis
How it works

The web script handling the '/goform/Mail_Test' endpoint passes form parameters directly to a system call for the email tool without proper input validation. An attacker can provide crafted form data containing additional shell commands that will be executed by the device's operating system. The vulnerability is available without authentication, meaning any network user with access to the web interface can exploit it.

Impact

The attacker gains remote code execution (RCE) with root privileges on the vulnerable device, giving them full control over the device and stored data.

Mitigation & patch

D-Link manufacturer has announced end-of-life for the DNS-343 product line — no security patches will be released. It is recommended to immediately remove devices from operation or at least isolate them from public networks and untrusted network segments (e.g., restrict access to the web interface only from trusted IP addresses using a firewall). Ultimately, devices should be replaced with supported hardware from another manufacturer or a newer D-Link product line.

Who is affected

D-Link DNS-343 ShareCenter with firmware versions up to and including 1.05.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Dlink Dns 343

    HW
    Dlink
    all versions
  • Dlink Dns 343 Firmware

    OS
    Dlink
    ≤ 1.0.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2024-3272CRITICAL9.8⚠ KEVPL ✓same product

D-Link DNS-320L/325/327L/340L — zakodowane na stałe poświadczenia (hard-coded credentials)

CVE-2024-3273HIGH7.3⚠ KEVsame product

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320...

CVE-2026-5212HIGH7.4same product

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, D...

CVE-2026-5211HIGH7.4same product

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, ...

CVE-2026-5213HIGH7.4same product

A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, D...