PoC Index

CVE-2018-10823

HIGH 9.0EPSS 77.7%

An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
77.70% chance of exploitation in the next 30 days, 100th percentile
Nuclei
high · CWE-78
Published
2018-10-17
Updated
2024-08-05

Proof-of-concept exploits (2)

Nuclei templates (1)

ExploitDB entries (1)

References

Related