Vulnerability Description
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-860L Firmware | <= 1.10b04 |
| Dlink | Dir-860L | a1 |
| Dlink | Dir-865L Firmware | <= 1.08b01 |
| Dlink | Dir-865L | a1 |
| Dlink | Dir-868L Firmware | <= 1.12b04 |
| Dlink | Dir-868L | a1 |
| Dlink | Dir-880L Firmware | <= 1.08b04 |
| Dlink | Dir-880L | a1 |
Related Weaknesses (CWE)
References
- ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-860L/REVA/DIR-860L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-868L/REVA/DIR-868L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-865L/REVA/DIR-865L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-880L/REVA/DIR-880L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- https://github.com/TheBeeMan/Pwning-multiple-dlink-router-via-SOAP-protoExploitThird Party Advisory
- ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-860L/REVA/DIR-860L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-868L/REVA/DIR-868L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-865L/REVA/DIR-865L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-880L/REVA/DIR-880L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- https://github.com/TheBeeMan/Pwning-multiple-dlink-router-via-SOAP-protoExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-US Government Resource
FAQ
What is CVE-2018-6530?
CVE-2018-6530 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions...
How severe is CVE-2018-6530?
CVE-2018-6530 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-6530?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dir-860L Firmware, Dlink Dir-860L, Dlink Dir-865L Firmware, Dlink Dir-865L, Dlink Dir-868L Firmware.