Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-17442. PoCs published by Core Security.
AI-analyzed exploit summary The exploit demonstrates unauthenticated and authenticated remote code execution (RCE) via unrestricted file upload vulnerabilities in D-Link Central WiFiManager Software Controller. It includes PoC code for uploading malicious PHP files via FTP and a web interface, leading to arbitrary command execution.
Description
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.
Exploits (1)
The exploit demonstrates unauthenticated and authenticated remote code execution (RCE) via unrestricted file upload vulnerabilities in D-Link Central WiFiManager Software Controller. It includes PoC code for uploading malicious PHP files via FTP and a web interface, leading to arbitrary command execution.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H