CRITICAL

CVE-2018-19989

CVSS v3

9.8

CRITICAL

EPSS Score

32.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices. In the SetQoSSettings.php source code, the uplink parameter is saved in the /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth internal configuration memory without any regex checking. And in the bwc_tc_spq_start, bwc_tc_wfq_start, and bwc_tc_adb_start functions of the bwcsvcs.php source code, the data in /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth is used with the tc command without any regex checking. A vulnerable /HNAP1/SetQoSSettings XML message could have shell metacharacters in the uplink element such as the `telnetd` string.

Technical details

Published
5/13/2019

Frequently asked questions

What is CVE-2018-19989?

In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices. In the SetQoSSettings.php source code, the uplink parameter is saved in the /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth internal configuration memory without any regex checking. And in the bwc_tc_spq_start, bwc_tc_wfq_start, and bwc_tc_adb_start functions of the bwcsvcs.php source code, the data in /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth is used with the tc command without any regex checking. A vulnerable /HNAP1/SetQoSSettings XML message could have shell metacharacters in the uplink element such as the `telnetd` string.

Is CVE-2018-19989 actively exploited?

Active exploitation of CVE-2018-19989 has not been confirmed. The EPSS score is 32.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-19989?

CVE-2018-19989 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-19989 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.