CVE-2018-17786: Critical severity d-link dir-823g firmware vulnerability
Published Oct 2, 2018
·Updated
On D-Link DIR-823G devices, ExportSettings.sh, uploadsettings.cgi, GetDownLoadSyslog.sh, and uploadfirmware.cgi do not require authentication, which allows remote attackers to execute arbitrary code.
Affected Software
2 affected components
D-Link Dir-823g Firmware
Dlink Dir-823g
Event History
Oct 2, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-17786?
CVE-2018-17786 is a vulnerability on D-Link DIR-823G devices that allows remote attackers to execute arbitrary code.
2
What is the severity level of CVE-2018-17786?
CVE-2018-17786 has a severity level of critical with a score of 9.8.
3
Which software is affected by CVE-2018-17786?
D-Link DIR-823G devices with D-Link DIR-823G firmware are affected by CVE-2018-17786.
4
How can remote attackers exploit CVE-2018-17786?
Remote attackers can exploit CVE-2018-17786 to execute arbitrary code without authentication.
5
Is there a fix available for CVE-2018-17786?
At the moment, there is no information available about a fix for CVE-2018-17786.