CVSS v3
9.8
CRITICAL
EPSS Score
25.5 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B 2.05B02 devices. In the SetClientInfoDemo.php source code, the AudioMute and AudioEnble parameters are saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. It needs to bypass the wget command option with a single quote. A vulnerable /HNAP1/SetClientInfoDemo XML message could have single quotes and backquotes in the AudioMute or AudioEnable element, such as the '`telnetd`' string.
Technical details
- Published
- 2019-05-13
Frequently asked questions
What is CVE-2018-19988?
In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B 2.05B02 devices. In the SetClientInfoDemo.php source code, the AudioMute and AudioEnble parameters are saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. It needs to bypass the wget command option with a single quote. A vulnerable /HNAP1/SetClientInfoDemo XML message could have single quotes and backquotes in the AudioMute or AudioEnable element, such as the '`telnetd`' string.
Is CVE-2018-19988 actively exploited?
Active exploitation of CVE-2018-19988 has not been confirmed. The EPSS score is 25.5%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2018-19988?
CVE-2018-19988 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2018-19988 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2018 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).