First published: Wed Jul 10 2019(Updated: )
An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MTU field to SetWanSettings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-818lw Firmware | =2.06-betab01 | |
Dlink Dir-818lw |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13481 is a vulnerability discovered in D-Link DIR-818LW devices with firmware 2.06betab01, allowing command injection through shell metacharacters in the MTU field to SetWanSettings.
CVE-2019-13481 is classified as critical with a severity score of 8.8.
Exploiting CVE-2019-13481 requires authentication and involves injecting shell metacharacters in the MTU field to SetWanSettings.
Yes, D-Link DIR-818LW firmware 2.06betab01 is vulnerable to CVE-2019-13481.
To fix CVE-2019-13481, update the firmware of D-Link DIR-818LW devices to a version that addresses the vulnerability.