← All CVEs

CVE-2018-10823

high · 8.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.

8.8
CVSS
77.7%
EPSS (exploit prob.)
100th
EPSS percentile
2018-10-17
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
dlinkdwr-116_firmware<= 1.06
dlinkdwr-116all versions
dlinkdwr-512_firmware<= 2.02
dlinkdwr-512all versions
dlinkdwr-912_firmware<= 2.02
dlinkdwr-921all versions
dlinkdwr-111_firmware<= 1.01
dlinkdwr-111all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-10823