CVE-2018-19987: OS Command Injection
D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B0101i3seBETA, and DIR-890L Rev.A 1.21B02BETA devices mishandle IsAccessPoint in /HNAP1/SetAccessPointMode. In the SetAccessPointMode.php source code, the IsAccessPoint parameter is saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. A vulnerable /HNAP1/SetAccessPointMode XML message could have shell metacharacters in the IsAccessPoint element such as the telnetd string.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19987?
CVE-2018-19987 is a vulnerability that affects D-Link DIR-822, DIR-860L, DIR-868L, DIR-880L, and DIR-890L devices.
How does CVE-2018-19987 affect D-Link DIR-822 Rev.B 202KRb06 firmware?
CVE-2018-19987 affects D-Link DIR-822 Rev.B 202KRb06 firmware by mishandling the IsAccessPoint parameter in /HNAP1/SetAccessPointMode.
What is the severity of CVE-2018-19987?
CVE-2018-19987 has a severity rating of 9.8 (Critical).
How can I fix CVE-2018-19987 on my D-Link DIR-822 Rev.C 3.10B06?
To fix CVE-2018-19987 on your D-Link DIR-822 Rev.C 3.10B06, you should update the firmware to the latest version provided by D-Link.
Where can I find more information about CVE-2018-19987?
You can find more information about CVE-2018-19987 at the following link: [GitHub - pr0v3rbs/CVE](https://github.com/pr0v3rbs/CVE/tree/master/CVE-2018-19986%20-%2019990)