Vulnerability Description
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| D-Link | Dir-550A Firmware | <= 2.10kr |
| Dlink | Dir-550A | - |
| D-Link | Dir-604M Firmware | <= 2.10kr |
| Dlink | Dir-604M | - |
Related Weaknesses (CWE)
References
- https://fortiguard.com/zeroday/FG-VD-18-060Third Party Advisory
- https://fortiguard.com/zeroday/FG-VD-18-060Third Party Advisory
FAQ
What is CVE-2018-10967?
CVE-2018-10967 is a vulnerability with a CVSS score of 8.8 (HIGH). On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka r...
How severe is CVE-2018-10967?
CVE-2018-10967 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10967?
Check the references section above for vendor advisories and patch information. Affected products include: D-Link Dir-550A Firmware, Dlink Dir-550A, D-Link Dir-604M Firmware, Dlink Dir-604M.