CVE-2018-15515
HIGHD-Link Central WiFiManager CWM-100 <1.03 r0098 - Privilege Escalation
Title source: llmDescription
The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from the CaptivelPortal.exe subdirectory under the D-Link directory, which allows unprivileged local users to gain SYSTEM privileges.
References (2)
Core 2
Core References
Exploit, Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Nov/29
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/150244/D-LINK-Central-WifiManager-CWM-100-1.03-r0098-DLL-Hijacking.html
Scores
CVSS v3
7.8
EPSS
0.0064
EPSS Percentile
70.8%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
dlink/central_wifimanager
1.03_r0098
Published
Jan 31, 2019
Tracked Since
Feb 18, 2026