CVE-2019-12786: Command Injection
An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12786?
CVE-2019-12786 is a vulnerability that affects D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA firmware versions. It allows for command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.
How severe is CVE-2019-12786?
CVE-2019-12786 has a severity score of 8.8, which is considered high.
Which software versions are affected by CVE-2019-12786?
The D-Link DIR-818LW devices with firmware versions 2.05.B03 to 2.06B01 BETA are affected by CVE-2019-12786.
How can I fix CVE-2019-12786?
To fix CVE-2019-12786, users should update their D-Link DIR-818LW devices to a firmware version that is not affected by the vulnerability.
Where can I find more information about CVE-2019-12786?
More information about CVE-2019-12786 can be found at the following link: https://github.com/TeamSeri0us/pocs/blob/master/iot/dlink/dir818-protected.pdf