CVE Feed

    Dashboard / CVE / CVE-2018-19300

    CVE-2018-19300

    On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.

    Published:Apr 11, 2019
    Last Modified:Nov 21, 2024
    EPS:Apr 11, 2019
    EPSS Score:0.20754
    CVSS Score:9.8

    Affected Products

    Vendor
    D-link
    Product
    Dap-1530 Firmware
    Vendor
    D-link
    Product
    Dap-1610 Firmware
    Vendor
    D-link
    Product
    Dwr-116 Firmware
    Vendor
    D-link
    Product
    Dwr-711 Firmware
    Vendor
    Dlink
    Product
    Dap-1530
    Vendor
    Dlink
    Product
    Dap-1610
    Vendor
    Dlink
    Product
    Dwr-111
    Vendor
    Dlink
    Product
    Dwr-111 Firmware
    Vendor
    Dlink
    Product
    Dwr-116
    Vendor
    Dlink
    Product
    Dwr-116 Firmware
    Vendor
    Dlink
    Product
    Dwr-512
    Vendor
    Dlink
    Product
    Dwr-512 Firmware
    Vendor
    Dlink
    Product
    Dwr-711
    Vendor
    Dlink
    Product
    Dwr-712
    Vendor
    Dlink
    Product
    Dwr-712 Firmware
    Vendor
    Dlink
    Product
    Dwr-921
    Vendor
    Dlink
    Product
    Dwr-921 Firmware

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High