CVE-2019-13481: OS Command Injection
An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MTU field to SetWanSettings.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13481?
CVE-2019-13481 is a vulnerability discovered in D-Link DIR-818LW devices with firmware 2.06betab01, allowing command injection through shell metacharacters in the MTU field to SetWanSettings.
How severe is CVE-2019-13481?
CVE-2019-13481 is classified as critical with a severity score of 8.8.
How can I exploit CVE-2019-13481?
Exploiting CVE-2019-13481 requires authentication and involves injecting shell metacharacters in the MTU field to SetWanSettings.
Is D-Link DIR-818LW firmware 2.06betab01 vulnerable to CVE-2019-13481?
Yes, D-Link DIR-818LW firmware 2.06betab01 is vulnerable to CVE-2019-13481.
How can I fix CVE-2019-13481?
To fix CVE-2019-13481, update the firmware of D-Link DIR-818LW devices to a version that addresses the vulnerability.