CVE-2018-5371: OS Command Injection
diagping.cmd on D-Link DSL-2640U devices with firmware IM1.00 and ME1.00, and DSL-2540U devices with firmware ME1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5371?
CVE-2018-5371 has a severity score that indicates significant risk due to its potential for remote code execution.
How do I fix CVE-2018-5371?
To mitigate CVE-2018-5371, update the firmware of affected D-Link DSL-2540U and DSL-2640U devices to the latest secure version.
Which devices are affected by CVE-2018-5371?
CVE-2018-5371 impacts D-Link DSL-2540U devices with firmware ME_1.00 and D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00.
Can CVE-2018-5371 be exploited remotely?
Yes, CVE-2018-5371 allows authenticated remote attackers to execute arbitrary OS commands.
What is the impact of CVE-2018-5371 on D-Link devices?
The impact of CVE-2018-5371 includes the potential unauthorized execution of OS commands, compromising device security.