CVE-2018-19989: OS Command Injection
In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices. In the SetQoSSettings.php source code, the uplink parameter is saved in the /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth internal configuration memory without any regex checking. And in the bwctcspqstart, bwctcwfqstart, and bwctcadbstart functions of the bwcsvcs.php source code, the data in /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth is used with the tc command without any regex checking. A vulnerable /HNAP1/SetQoSSettings XML message could have shell metacharacters in the uplink element such as the telnetd string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19989?
The severity of CVE-2018-19989 is critical with a severity value of 9.8.
Which devices are affected by CVE-2018-19989?
D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices are affected by CVE-2018-19989.
What is the vulnerability type of CVE-2018-19989?
The vulnerability type of CVE-2018-19989 is CWE-78.
How can I fix CVE-2018-19989?
To fix CVE-2018-19989, update the firmware of D-Link DIR-822 Rev.B to version 202KRb06 or higher and DIR-822 Rev.C to version 3.10B06 or higher.
Where can I find more information about CVE-2018-19989?
You can find more information about CVE-2018-19989 at the following link: [GitHub - CVE-2018-19986 - 19990](https://github.com/pr0v3rbs/CVE/tree/master/CVE-2018-19986%20-%2019990)