9
CVSSv2

CVE-2018-5371

Published: 12/01/2018 Updated: 14/02/2024
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote malicious users to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.

Vulnerable Product Search on Vulmon Subscribe to Product

d-link dsl-2540u_firmware me_1.00

d-link dsl-2640u_firmware im_1.00

d-link dsl-2640u_firmware me_1.00