← Back

CVE-2018-5371

nvd nist
Published: Jan 12, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.

Affected (3)

2 products
Dsl 2540u Firmware
Dsl 2640u Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version me_1.00
Running on/withPlatform Versions
Dlink
Dsl 2540u
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
D Link
Version im_1.00
Version me_1.00
Running on/withPlatform Versions
Dlink
Dsl 2640u
All versions

References (2)

Source: cve@mitre.org
ExploitTechnical DescriptionThird Party AdvisoryURL Repurposed
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party AdvisoryURL Repurposed

Timeline

No history available yet.