PT-2018-3894 · D Link · D-Link Dir-846

Published

2018-09-03

·

Updated

2023-04-26

·

CVE-2018-16408

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-846 version 100.26
Description The issue exists due to the lack of measures to neutralize special elements used in an operating system command. This can be exploited by a remote attacker to execute arbitrary code. The exploitation can occur via a SetNetworkTomographySettings request, leveraging admin access.
Recommendations For D-Link DIR-846 version 100.26, consider restricting access to the SetNetworkTomographySettings request to minimize the risk of exploitation until a patch is available. Additionally, limiting admin access can help reduce the vulnerability to arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-02948
CVE-2018-16408

Affected Products

D-Link Dir-846