PT-2018-2190 · D Link · D-Link Central Wifimanager Cwm-100
Hyp3Rlinx
+1
·
Published
2018-08-08
·
Updated
2019-10-03
·
CVE-2018-15515
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link Central WiFiManager CWM-100 version 1.03 r0098
Description
The issue is related to the CaptivelPortal service, which loads a Trojan horse
quserex.dll from the CaptivelPortal.exe subdirectory. This allows unprivileged local users to gain SYSTEM privileges. The vulnerability is also associated with errors in loading the quserex.dll library, which can be exploited to execute arbitrary code using a specially crafted file.Recommendations
For D-Link Central WiFiManager CWM-100 version 1.03 r0098, consider disabling the CaptivelPortal service as a temporary workaround until a patch is available. Restrict access to the
quserex.dll library to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Central Wifimanager Cwm-100