CRITICAL · 9.8

CVE-2018-19300

On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-...

Vulnerability Description

On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
D-LinkDap-1530 Firmware<= 1.05
DlinkDap-1530-
D-LinkDap-1610 Firmware<= 1.05
DlinkDap-1610-
DlinkDwr-111 Firmware<= 1.01
DlinkDwr-111-
D-LinkDwr-116 Firmware1.06
DlinkDwr-116 Firmware<= 1.05
DlinkDwr-116-
DlinkDwr-512 Firmware<= 2.02
DlinkDwr-512-
D-LinkDwr-711 Firmware<= 1.11
DlinkDwr-711-
DlinkDwr-712 Firmware<= 2.02
DlinkDwr-712-
DlinkDwr-921 Firmware<= 1.02
DlinkDwr-921-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-19300?

CVE-2018-19300 is a vulnerability with a CVSS score of 9.8 (CRITICAL). On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-...

How severe is CVE-2018-19300?

CVE-2018-19300 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-19300?

Check the references section above for vendor advisories and patch information. Affected products include: D-Link Dap-1530 Firmware, Dlink Dap-1530, D-Link Dap-1610 Firmware, Dlink Dap-1610, Dlink Dwr-111 Firmware.