CVE-2018-10967
 
Severity Score
8.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.
En los dispositivos D-Link DIR-550A y DIR-604M hasta la versión v2.10KR, un usuario malicioso puede falsificar una petición HTTP para inyectar comandos del sistema operativo que pueden ejecutarse en el dispositivo con mayores privilegios. Esto también se conoce como ejecución remota de código.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-05-10 CVE Reserved
- 2018-05-18 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://fortiguard.com/zeroday/FG-VD-18-060 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
D-link Search vendor "D-link" | Dir-550a Firmware Search vendor "D-link" for product "Dir-550a Firmware" | <= 2.10kr Search vendor "D-link" for product "Dir-550a Firmware" and version " <= 2.10kr" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dir-550a Search vendor "Dlink" for product "Dir-550a" | - | - |
Safe
|
D-link Search vendor "D-link" | Dir-604m Firmware Search vendor "D-link" for product "Dir-604m Firmware" | <= 2.10kr Search vendor "D-link" for product "Dir-604m Firmware" and version " <= 2.10kr" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dir-604m Search vendor "Dlink" for product "Dir-604m" | - | - |
Safe
|