CVE-2018-19300: Input Validation
On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCUSHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCUSHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19300?
CVE-2018-19300 is classified as a remote command execution vulnerability that poses a high risk to affected D-Link devices.
How do I fix CVE-2018-19300?
To fix CVE-2018-19300, update the affected D-Link firmware to the latest version provided by the manufacturer.
Which D-Link devices are affected by CVE-2018-19300?
CVE-2018-19300 affects D-Link DAP-1530, DAP-1610, DWR-111, DWR-116, DWR-512, DWR-711, and DWR-712 devices among others.
Can CVE-2018-19300 be exploited remotely?
Yes, CVE-2018-19300 can be exploited remotely, allowing attackers to execute arbitrary commands on the affected devices.
Is there a patch available for CVE-2018-19300?
Yes, D-Link has released patches for CVE-2018-19300 in firmware updates that must be applied to vulnerable devices.