CVE-2019-12787: OS Command Injection
Published Jun 10, 2019
·Updated
An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the Gateway key.
Affected Software
3 affected components
Dlink Dir-818lw Firmware=2.05.b03
Dlink Dir-818lw Firmware=2.06b01-beta
Dlink Dir-818lw
Event History
Jun 10, 2019
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12787?
CVE-2019-12787 is a vulnerability discovered on D-Link DIR-818LW devices, allowing command injection in HNAP1 SetWanSettings via an XML injection of the value of the Gateway key.
2
How severe is CVE-2019-12787?
CVE-2019-12787 has a severity score of 8.8 (High).
3
Which software versions are affected?
Software versions 2.05.B03 to 2.06B01 BETA of D-Link DIR-818LW devices are affected.
4
How can I fix CVE-2019-12787?
It is recommended to update the D-Link DIR-818LW firmware to a version that fixes the vulnerability.
5
Where can I find more information about CVE-2019-12787?
You can find more information about CVE-2019-12787 on the GitHub page of TeamSeri0us.