First published: Wed Jun 20 2018(Updated: )
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is possible as a result of incorrect processing of the res_buf parameter to index.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-620 Firmware | =1.0.3 | |
D-Link DIR-620 Firmware | =1.0.37 | |
D-Link DIR-620 Firmware | =1.3.1 | |
D-Link DIR-620 Firmware | =1.3.3 | |
D-Link DIR-620 Firmware | =1.3.7 | |
D-Link DIR-620 Firmware | =1.4.0 | |
D-Link DIR-620 Firmware | =2.0.22 | |
dlink DIR-620 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6211 has been classified as a critical vulnerability due to the potential for OS command injection that allows unauthorized execution of commands.
To fix CVE-2018-6211, update the D-Link DIR-620 firmware to the latest version provided by the manufacturer.
CVE-2018-6211 affects D-Link DIR-620 devices running customized firmware versions 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22.
CVE-2018-6211 can be exploited to perform OS command injection attacks, allowing attackers to execute arbitrary commands on the affected devices.
There is no known workaround for CVE-2018-6211; upgrading the firmware is the only mitigation available.