← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-19987

D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-890L Rev.A 1.21B02_BETA devices mishandle IsAccessPoint in /HNAP1/SetAccessPointMode. In the SetAccessPointMode.php source code, the IsAccessPoint parameter is saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. A vulnerable /HNAP1/SetAccessPointMode XML message could have shell metacharacters in the IsAccessPoint element such as the `telnetd` string.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:12.93%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
d-link dir-818lw_firmware 2.05.b03
dlink dir-818lw all
d-link dir-822_firmware 202krb06
dlink dir-822_firmware 3.10b06
dlink dir-822 all
d-link dir-860l_firmware 2.03.b03
dlink dir-860l all
d-link dir-868l_firmware 2.05b02
dlink dir-868l all
d-link dir-880l_firmware 1.20b01_01_i3se
dlink dir-880l all
d-link dir-890l\/r_firmware 1.21b02
dlink dir-890l\/r all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
12.932%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2018-12-09T00:00:00
Published2019-05-13T13:23:33
Last Updated2024-08-05T11:51:17

LINK COPIED TO CLIPBOARD