First published: Tue Oct 02 2018(Updated: )
On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is sent directly to the "system" library function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-link Dir-823g Firmware | ||
Dlink Dir-823g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17787 is a vulnerability found on D-Link DIR-823G devices that allows command injection via shell metacharacters in the POST data.
CVE-2018-17787 has a severity rating of 9.8 (Critical).
The D-Link DIR-823G firmware is affected by CVE-2018-17787.
To fix CVE-2018-17787, it is recommended to update the firmware of your D-Link DIR-823G device to the latest version.
No, the Dlink Dir-823g device is not vulnerable to CVE-2018-17787.