CVE-2018-18008: Critical severity d-link dsl-2770l firmware vulnerability
Published Dec 21, 2018
·Updated
spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials.
Affected Software
32 affected components
Dlink Dsl-2770l Firmware=me_1.01
Dlink Dsl-2770l Firmware=me_1.02
Dlink Dsl-2770l Firmware=me_1.06
Dlink Dsl-2770l
Dlink Dir-140l Firmware=1.00
Dlink Dir-140l Firmware=1.01ru
Dlink Dir-140l Firmware=1.02
Dlink Dir-140l
Dlink Dir-640l Firmware=1.00
Dlink Dir-640l Firmware=1.01ru
Dlink Dir-640l Firmware=1.02
Dlink Dir-640l
Dlink Dwr-116 Firmware=1.03
Dlink Dwr-116 Firmware=1.05
Dlink Dwr-116 Firmware=2.01
Dlink Dwr-116 Firmware=2.02
Dlink Dwr-116
Dlink Dwr-512 Firmware=1.03
Dlink Dwr-512 Firmware=1.05
Dlink Dwr-512 Firmware=2.01
Dlink Dwr-512 Firmware=2.02
Dlink Dwr-512
Dlink Dwr-555 Firmware=1.03
Dlink Dwr-555 Firmware=1.05
Dlink Dwr-555 Firmware=2.01
Dlink Dwr-555 Firmware=2.02
Dlink Dwr-555
Dlink Dwr-921 Firmware=1.03
Dlink Dwr-921 Firmware=1.05
Dlink Dwr-921 Firmware=2.01
Dlink Dwr-921 Firmware=2.02
Dlink Dwr-921
Event History
Dec 21, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18008?
CVE-2018-18008 has a high severity due to its potential for remote unauthenticated access to admin credentials.
2
How do I fix CVE-2018-18008?
To mitigate CVE-2018-18008, update your affected D-Link devices to the latest firmware versions provided by D-Link.
3
Which D-Link devices are affected by CVE-2018-18008?
CVE-2018-18008 affects multiple D-Link devices including DSL-2770L, DIR-140L, DIR-640L, DWR-116, DWR-512, DWR-555, and DWR-921.
4
Can CVE-2018-18008 be exploited remotely?
Yes, CVE-2018-18008 can be exploited by remote unauthenticated attackers.
5
What is the potential impact of CVE-2018-18008?
The potential impact of CVE-2018-18008 is unauthorized access to administrative functions on the affected D-Link devices.