CVE-2018-6211
published 2018-06-20CVE-2018-6211: On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is…
PriorityP346high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
5.77%
92.2th percentile
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is possible as a result of incorrect processing of the res_buf parameter to index.cgi.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dir-620_firmware | — | — |
| d-link | dir-620_firmware | — | — |
| d-link | dir-620_firmware | — | — |
| d-link | dir-620_firmware | — | — |
| d-link | dir-620_firmware | — | — |
| d-link | dir-620_firmware | — | — |
| d-link | dir-620_firmware | — | — |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Securelist
Backdoors in D-Link’s backyard
blogs_securelist·2018-05-23
Backdoors in D-Link’s backyard
Table of Contents
- The impact of vulnerabilities
- The object of research
- Technical details
- How to fix it
- Advisory Status
Authors
- Denis Makrushin
## Multiple vulnerabilities in D-Link DIR-620 router
“If you want to change the world, start with yourself.” In the case of security research this can be rephrased to: “If you want to make the world safer, start with the smart things in your home.” Or, to be more specific, start with your router – the core of any home network as well as an interesting research object. And that router you got from your ISP as part of your internet contract is even more interesting when it comes to research.
## The impact of vulnerabilities
Note: the following information about vulnerabilities has been submitted to the respective stakeholders (D-Li
Securelist
Backdoors in D-Link’s backyard
blogs_securelist·2018-05-23·CVSS 9.8
CVE-2018-6212 [CRITICAL] Backdoors in D-Link’s backyard
Table of Contents
The impact of vulnerabilities
The object of research
Technical details
Weakness in user data validation (reflected cross-site scripting) (CVE-2018-6212)
Hardcoded default credentials for web dashboard (CVE-2018-6213)
OS command injection (CVE-2018-6211)
Hardcoded default credentials for Telnet (CVE-2018-6210)
How to fix it
Advisory Status
Authors
Denis Makrushin
## Multiple vulnerabilities in D-Link DIR-620 router
“If you want to change the world, start with yourself.” In the case of security research this can be rephrased to: “If you want to make the world safer, start with the smart things in your home.” Or, to be more specific, start with your router – the core of any home network as well as an interesting research object. And that router you got from your
http://www.securitynewspaper.com/2018/05/25/d-link-dir-620-routers-critical-vulnerabilities/https://securelist.com/backdoors-in-d-links-backyard/85530/https://securityaffairs.co/wordpress/72839/hacking/d-link-dir-620-flaws.htmlhttps://www.bleepingcomputer.com/news/security/backdoor-account-found-in-d-link-dir-620-routers/http://www.securitynewspaper.com/2018/05/25/d-link-dir-620-routers-critical-vulnerabilities/https://securelist.com/backdoors-in-d-links-backyard/85530/https://securityaffairs.co/wordpress/72839/hacking/d-link-dir-620-flaws.htmlhttps://www.bleepingcomputer.com/news/security/backdoor-account-found-in-d-link-dir-620-routers/
2018-06-20
Published