PT-2018-2076 · D Link · D-Link Central Wifi Manager

Julian Muñoz

·

Published

2018-06-04

·

Updated

2023-04-26

·

CVE-2018-17440

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link Central WiFi Manager versions prior to 1.03r0100-Beta1
Description The issue is related to the use of hardcoded credentials for the FTP service, which runs on port 9000. This allows a remote attacker to execute arbitrary PHP code by uploading a file to the web root directory and then accessing it. The hardcoded credentials used are admin for both the username and password.
Recommendations For versions prior to 1.03r0100-Beta1, update to version 1.03r0100-Beta1 or later to resolve the issue. As a temporary workaround, consider changing the default FTP credentials and restricting access to the FTP server on port 9000 to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00026
CVE-2018-17440

Affected Products

D-Link Central Wifi Manager