First published: Mon Apr 01 2019(Updated: )
An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated attacker to execute arbitrary OS commands via the ScrIPaddrEndTXT parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dsl-3782 Firmware | =1.01 | |
Dlink Dsl-3782 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17990 refers to an OS command injection vulnerability in D-Link DSL-3782 devices with firmware 1.01.
The severity of the CVE-2018-17990 vulnerability is critical with a CVSS score of 8.8.
D-Link DSL-3782 devices with firmware 1.01 are affected by CVE-2018-17990.
An authenticated attacker can exploit the CVE-2018-17990 vulnerability by executing arbitrary OS commands via the ScrIPaddrEndTXT parameter in Acl.asp.
At the moment, there is no information available regarding a fix for the CVE-2018-17990 vulnerability. It is recommended to apply any available security patches from the vendor and follow best practices to mitigate the risks associated with the vulnerability.