CVE-2018-10823: OS Command Injection
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10823?
CVE-2018-10823 has a high severity level due to its potential for remote code execution.
How do I fix CVE-2018-10823?
To fix CVE-2018-10823, update the firmware of your D-Link devices to the latest version available.
Which D-Link devices are affected by CVE-2018-10823?
CVE-2018-10823 affects D-Link DWR-116, DWR-512, DWR-712, DWR-912, DWR-921, and DWR-111 models running specific firmware versions.
Can an attacker exploit CVE-2018-10823 without authentication?
No, CVE-2018-10823 requires authentication for an attacker to execute arbitrary code.
Is CVE-2018-10823 a local or remote attack?
CVE-2018-10823 is considered a remote attack since it can be executed over the network once the attacker is authenticated.