First published: Mon Jun 10 2019(Updated: )
An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-818lw Firmware | =2.05.b03 | |
Dlink Dir-818lw Firmware | =2.06b01-beta | |
Dlink Dir-818lw |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12786 is a vulnerability that affects D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA firmware versions. It allows for command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.
CVE-2019-12786 has a severity score of 8.8, which is considered high.
The D-Link DIR-818LW devices with firmware versions 2.05.B03 to 2.06B01 BETA are affected by CVE-2019-12786.
To fix CVE-2019-12786, users should update their D-Link DIR-818LW devices to a firmware version that is not affected by the vulnerability.
More information about CVE-2019-12786 can be found at the following link: https://github.com/TeamSeri0us/pocs/blob/master/iot/dlink/dir818-protected.pdf