Sploitus

CVE-2018-17066

No indexed exploits for CVE-2018-17066 yet

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/form2systime.cgi route. This could lead to command injection via shell metacharacters in the datetime parameter.

Affected products
D-Link Dir-816 A2
Dlink dir-816 a2 Firmware
= 1.10_b05
CVSS 2.0
10.0 HIGH
CVSS 3.1
9.8 CRITICAL
EPSS
7.3% (94th percentile)
Weakness
CWE-78
NVD status
Modified
Published
2018-09-15
CVE-2018-17066 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2018-17066 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2018-17066 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.