CVE-2018-6211: Command Injection
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is possible as a result of incorrect processing of the resbuf parameter to index.cgi.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6211?
CVE-2018-6211 has been classified as a critical vulnerability due to the potential for OS command injection that allows unauthorized execution of commands.
How do I fix CVE-2018-6211?
To fix CVE-2018-6211, update the D-Link DIR-620 firmware to the latest version provided by the manufacturer.
What devices are affected by CVE-2018-6211?
CVE-2018-6211 affects D-Link DIR-620 devices running customized firmware versions 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22.
What kind of attack can be executed through CVE-2018-6211?
CVE-2018-6211 can be exploited to perform OS command injection attacks, allowing attackers to execute arbitrary commands on the affected devices.
Is there a workaround for CVE-2018-6211?
There is no known workaround for CVE-2018-6211; upgrading the firmware is the only mitigation available.