CRITICAL · 9.8

CVE-2018-6530

OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions...

Vulnerability Description

OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DlinkDir-860L Firmware<= 1.10b04
DlinkDir-860La1
DlinkDir-865L Firmware<= 1.08b01
DlinkDir-865La1
DlinkDir-868L Firmware<= 1.12b04
DlinkDir-868La1
DlinkDir-880L Firmware<= 1.08b04
DlinkDir-880La1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-6530?

CVE-2018-6530 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions...

How severe is CVE-2018-6530?

CVE-2018-6530 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-6530?

Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dir-860L Firmware, Dlink Dir-860L, Dlink Dir-865L Firmware, Dlink Dir-865L, Dlink Dir-868L Firmware.