9
CVSSv2

CVE-2018-6211

Published: 20/06/2018 Updated: 26/04/2023
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is possible as a result of incorrect processing of the res_buf parameter to index.cgi.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

d-link dir-620_firmware 1.0.3

d-link dir-620_firmware 1.0.37

d-link dir-620_firmware 1.3.1

d-link dir-620_firmware 1.3.3

d-link dir-620_firmware 1.3.7

d-link dir-620_firmware 1.4.0

d-link dir-620_firmware 2.0.22