CVE-2018-16408: OS Command Injection
Published Sep 3, 2018
·Updated
D-Link DIR-846 devices with firmware 100.26 allow remote attackers to execute arbitrary code as root via a SetNetworkTomographySettings request by leveraging admin access.
Affected Software
2 affected components
D-Link Dir-846 Firmware=100.26
Dlink Dir-846
Event History
Sep 3, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16408?
CVE-2018-16408 is a vulnerability in D-Link DIR-846 devices with firmware 100.26 that allows remote attackers to execute arbitrary code as root.
2
How severe is CVE-2018-16408?
CVE-2018-16408 has a severity value of 7.2, which is considered critical.
3
How can an attacker exploit CVE-2018-16408?
An attacker can exploit CVE-2018-16408 by leveraging admin access and sending a SetNetworkTomographySettings request to the device.
4
Is D-Link DIR-846 firmware version 100.26 affected by CVE-2018-16408?
Yes, D-Link DIR-846 devices with firmware version 100.26 are affected by CVE-2018-16408.
5
Is there a fix for CVE-2018-16408?
At the moment, there is no available fix for CVE-2018-16408. It is recommended to contact the vendor for further information.