CVE-2018-17990: Command Injection
An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated attacker to execute arbitrary OS commands via the ScrIPaddrEndTXT parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17990?
CVE-2018-17990 refers to an OS command injection vulnerability in D-Link DSL-3782 devices with firmware 1.01.
How severe is the vulnerability CVE-2018-17990?
The severity of the CVE-2018-17990 vulnerability is critical with a CVSS score of 8.8.
Which devices are affected by CVE-2018-17990?
D-Link DSL-3782 devices with firmware 1.01 are affected by CVE-2018-17990.
How can an attacker exploit the CVE-2018-17990 vulnerability?
An authenticated attacker can exploit the CVE-2018-17990 vulnerability by executing arbitrary OS commands via the ScrIPaddrEndTXT parameter in Acl.asp.
Is there a fix available for the CVE-2018-17990 vulnerability?
At the moment, there is no information available regarding a fix for the CVE-2018-17990 vulnerability. It is recommended to apply any available security patches from the vendor and follow best practices to mitigate the risks associated with the vulnerability.