CRITICAL

CVE-2018-19988

CVSS v3

9.8

CRITICAL

EPSS Score

25.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B 2.05B02 devices. In the SetClientInfoDemo.php source code, the AudioMute and AudioEnble parameters are saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. It needs to bypass the wget command option with a single quote. A vulnerable /HNAP1/SetClientInfoDemo XML message could have single quotes and backquotes in the AudioMute or AudioEnable element, such as the '`telnetd`' string.

Technical details

Published
5/13/2019

Frequently asked questions

What is CVE-2018-19988?

In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B 2.05B02 devices. In the SetClientInfoDemo.php source code, the AudioMute and AudioEnble parameters are saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. It needs to bypass the wget command option with a single quote. A vulnerable /HNAP1/SetClientInfoDemo XML message could have single quotes and backquotes in the AudioMute or AudioEnable element, such as the '`telnetd`' string.

Is CVE-2018-19988 actively exploited?

Active exploitation of CVE-2018-19988 has not been confirmed. The EPSS score is 25.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-19988?

CVE-2018-19988 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-19988 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.