Vulnerability Description
diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| D-Link | Dsl-2540U Firmware | me_1.00 |
| Dlink | Dsl-2540U | - |
| D-Link | Dsl-2640U Firmware | im_1.00 |
| Dlink | Dsl-2640U | - |
Related Weaknesses (CWE)
References
- https://www.iplantom.com/2018/01/10/dsl2640U/ExploitTechnical DescriptionThird Party Advisory
- https://www.iplantom.com/2018/01/10/dsl2640U/ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2018-5371?
CVE-2018-5371 is a vulnerability with a CVSS score of 8.8 (HIGH). diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via she...
How severe is CVE-2018-5371?
CVE-2018-5371 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5371?
Check the references section above for vendor advisories and patch information. Affected products include: D-Link Dsl-2540U Firmware, Dlink Dsl-2540U, D-Link Dsl-2640U Firmware, Dlink Dsl-2640U.