PT-2019-1116 · D Link · D-Link Dir-860L+1

Pr0V3Rbs

·

Published

2019-01-02

·

Updated

2021-04-23

·

CVE-2018-20114

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: D-Link DIR-818LW Rev.A version 2.05.B03 D-Link DIR-860L Rev.B version 2.03.B03
Description: The issue allows for unauthenticated remote OS command execution in the soap.cgi service of the cgibin binary. This can be achieved via an "&&" substring in the service parameter. The problem arises due to incomplete privilege management in the soapcgi main function of the soap.cgi script, located at /htdocs/cgibin/soap.cgi, which can enable a remote attacker to execute arbitrary OS commands.
Recommendations: For D-Link DIR-818LW Rev.A version 2.05.B03, consider disabling the soap.cgi service until a patch is available. For D-Link DIR-860L Rev.B version 2.03.B03, restrict access to the cgibin binary to minimize the risk of exploitation. Avoid using the service parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00093
CVE-2018-20114

Affected Products

D-Link Dir-818Lw
D-Link Dir-860L