CVE-2018-5371
diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 42.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 41.99% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- d-link/dsl-2540u firmware · d-link/dsl-2640u firmware
- Source
- cve@mitre.org
References
- https://www.iplantom.com/2018/01/10/dsl2640U/Exploit, Technical Description, Third Party Advisory, URL Repurposed
- https://www.iplantom.com/2018/01/10/dsl2640U/Exploit, Technical Description, Third Party Advisory, URL Repurposed
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.