CRITICAL

CVE-2018-19987

CVSS v3

9.8

CRITICAL

EPSS Score

81.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-890L Rev.A 1.21B02_BETA devices mishandle IsAccessPoint in /HNAP1/SetAccessPointMode. In the SetAccessPointMode.php source code, the IsAccessPoint parameter is saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. A vulnerable /HNAP1/SetAccessPointMode XML message could have shell metacharacters in the IsAccessPoint element such as the `telnetd` string.

Technical details

Published
5/13/2019

Frequently asked questions

What is CVE-2018-19987?

D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-890L Rev.A 1.21B02_BETA devices mishandle IsAccessPoint in /HNAP1/SetAccessPointMode. In the SetAccessPointMode.php source code, the IsAccessPoint parameter is saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. A vulnerable /HNAP1/SetAccessPointMode XML message could have shell metacharacters in the IsAccessPoint element such as the `telnetd` string.

Is CVE-2018-19987 actively exploited?

Active exploitation of CVE-2018-19987 has not been confirmed. The EPSS score is 81.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-19987?

CVE-2018-19987 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-19987 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.