CVE-2018-19986
In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices. In the SetRouterSettings.php source code, the RemotePort parameter is saved in the $path_inf_wan1."/web" internal configuration memory without any regex checking. And in the IPTWAN_build_command function of the iptwan.php source code, the data in $path_inf_wan1."/web" is used with the iptables command without any regex checking. A vulnerable /HNAP1/SetRouterSettings XML message could have shell metacharacters in the RemotePort element such as the `telnetd` string.
- Affected products
- D-Link Dir-818Lw, D-Link Dir-822
- D-link dir-818lw Firmware
- = 2.05.b03
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 41.6% (99th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2019-05-13
CVE-2018-19986 at NVD
1 known exploit for CVE-2018-19986
Proof-of-concept code and exploit modules indexed by Sploitus