CVE-2018-10431: OS Command Injection
Published Apr 26, 2018
·Updated
D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen.
Affected Software
2 affected components
D-Link Dir-615 Firmware=2.5.17
Dlink Dir-615
Event History
Apr 26, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10431?
The severity of CVE-2018-10431 is classified as high due to the potential for remote code execution.
2
How do I fix CVE-2018-10431?
To fix CVE-2018-10431, update the D-Link DIR-615 firmware to the latest available version.
3
What devices are affected by CVE-2018-10431?
CVE-2018-10431 affects D-Link DIR-615 devices running firmware version 2.5.17.
4
What type of vulnerability is CVE-2018-10431?
CVE-2018-10431 is classified as a remote code execution vulnerability.
5
Can CVE-2018-10431 be exploited remotely?
Yes, CVE-2018-10431 can be exploited remotely through the vulnerable Traceroute feature.