CVE-2018-10823
D-Link dwr-116_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2018-10823 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dwr-116_firmwareBrowse D-Link / dwr-116_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBD-Link Routers - Command InjectionExploitDB exploitby Blazej AdamczykNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHD-Link Routers - Remote Command InjectionCVSS 8.8
D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 device may allow an authenticated attacker to execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access, data theft, and complete compromise of the affected router.
Remediation
Apply the latest firmware update provided by D-Link to mitigate this vulnerability.
Source: ProjectDiscovery