HIGH · 8.8

CVE-2018-10823

An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attac...

Vulnerability Description

An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DlinkDwr-116 Firmware<= 1.06
DlinkDwr-116-
DlinkDwr-512 Firmware<= 2.02
DlinkDwr-512-
DlinkDwr-912 Firmware<= 2.02
DlinkDwr-921-
DlinkDwr-111 Firmware<= 1.01
DlinkDwr-111-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-10823?

CVE-2018-10823 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attac...

How severe is CVE-2018-10823?

CVE-2018-10823 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-10823?

Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dwr-116 Firmware, Dlink Dwr-116, Dlink Dwr-512 Firmware, Dlink Dwr-512, Dlink Dwr-912 Firmware.