CVE-2018-6530: D-Link Multiple Routers OS Command Injection Vulnerability
Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.
Other sources
OS command injection vulnerability in soap.cgi (soapcgimain in cgibin) in D-Link DIR-880L DIR-880LREVAFIRMWAREPATCH1.08B04 and previous versions, DIR-868L DIR868LA1FW112b04 and previous versions, DIR-65L DIR-865LREVAFIRMWAREPATCH1.08.B01 and previous versions, and DIR-860L DIR860LA1FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DIR-880Lto a version that resolves this vulnerability.Fixed in DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 - Upgrade
Upgrade
D-Link DIR-868Lto a version that resolves this vulnerability.Fixed in DIR868LA1_FW112b04 - Upgrade
Upgrade
D-Link DIR-65Lto a version that resolves this vulnerability.Fixed in DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 - Upgrade
Upgrade
D-Link DIR-860Lto a version that resolves this vulnerability.Fixed in DIR860LA1_FW110b04 - Compensating control
If the affected device has entered end-of-life, disconnect it if still in use.
- Compensating control
Verify that the vendor’s fix under CVE-2018-20114 is applied so it properly patches the KEV entry CVE-2018-6530.
Event History
Frequently Asked Questions
What is CVE-2018-6530?
CVE-2018-6530 is a critical OS command injection vulnerability in multiple D-Link routers.
Which D-Link routers are affected by CVE-2018-6530?
CVE-2018-6530 affects D-Link DIR-880L, DIR-868L, DIR-865L, and DIR-860L routers.
What is the severity of CVE-2018-6530?
CVE-2018-6530 has a severity rating of 9.8 (critical).
How can I fix CVE-2018-6530?
To fix CVE-2018-6530, you should apply the latest firmware updates provided by D-Link.
Where can I find more information about CVE-2018-6530?
You can find more information about CVE-2018-6530 on the D-Link support announcement and GitHub repository links provided in the references.