CVE-2019-13372
published 2019-07-06CVE-2019-13372: /web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via…
PriorityP192critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
82.49%
99.6th percentile
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | central_wifimanager | <= 1.03 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via the `username` cookie field, which is passed to PHP `eval()` without sanitization. Monitor HTTP requests to `/index.php/Index/index` containing a `username` cookie with PHP injection payloads (e.g., URL-encoded semicolons `%3b`, PHP function calls) and an empty `password` cookie value. ↗
- →Authentication bypass is achieved by supplying an empty `password` cookie value alongside the malicious `username` cookie. Detect requests where the `password` cookie is empty and the `username` cookie contains special characters indicative of PHP injection (e.g., `%3b`, `//`, parentheses). ↗
- →Use the Shodan dork `html:"D-Link Central WiFiManager"` to identify exposed instances of the vulnerable product on the internet. ↗
- ·Affected versions are strictly below v1.03R0100_BETA6. Instances running v1.03R0100_BETA6 or later are not vulnerable. ↗
- ·Exploitation is only possible because dangerous PHP functions are not disabled by default on the target. If `disable_functions` is configured in `php.ini` to restrict dangerous functions (e.g., `system`, `exec`, `passthru`), code execution impact may be limited, though the eval injection itself would still be present. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j37h-vwh2-59wm: /web/Lib/Action/IndexAction
ghsa_unreviewed·2022-05-24
CVE-2019-13372 [CRITICAL] CWE-287 GHSA-j37h-vwh2-59wm: /web/Lib/Action/IndexAction
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.
VulnCheck
D-Link central_wifimanager Improper Control of Generation of Code ('Code Injection')
vulncheck·2019·CVSS 9.8
CVE-2019-13372 [CRITICAL] D-Link central_wifimanager Improper Control of Generation of Code ('Code Injection')
D-Link central_wifimanager Improper Control of Generation of Code ('Code Injection')
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.
Affected: D-Link central_wifimanager
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://unit42.paloaltonetworks.com/network-attack-trends-winter-2020/; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2025-08-10&host_type=src&vulnerability=cve-2019-13372; https://dashboa
No detection rules found.
Metasploit
D-Link Central WiFi Manager CWM(100) RCE
metasploit
D-Link Central WiFi Manager CWM(100) RCE
D-Link Central WiFi Manager CWM(100) RCE
This module exploits a PHP code injection vulnerability in D-Link Central WiFi Manager CWM(100) versions below `v1.03R0100_BETA6`. The vulnerability exists in the username cookie, which is passed to `eval()` without being sanitized. Dangerous functions are not disabled by default, which makes it possible to get code execution on the target.
Nuclei
D-Link Central WiFi Manager CWM(100) - Remote Code Execution
nuclei·CVSS 9.8
CVE-2019-13372 [CRITICAL] D-Link Central WiFi Manager CWM(100) - Remote Code Execution
D-Link Central WiFi Manager CWM(100) - Remote Code Execution
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.
Template:
id: CVE-2019-13372
info:
name: D-Link Central WiFi Manager CWM(100) - Remote Code Execution
author: DhiyaneshDK
severity: critical
description: |
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.
impact: |
Unauthenticated attacke
Unit42
Network Attack Trends: Internet of Threats (November 2020-January 2021)
blogs_unit42·2021-04-12·CVSS 7.5
CVE-2020-28188 [HIGH] Network Attack Trends: Internet of Threats (November 2020-January 2021)
# Executive Summary
Unit 42 researchers analyzed network attack trends over Winter 2020 and discovered many interesting exploits in the wild. During the period of Nov. 2020 to Jan. 2021, the majority of the attacks we observed were classified as critical (75%), compared to the 50.4% we reported in the fall of 2020. Several newly observed exploits, including CVE-2020-28188, CVE-2020-17519, and CVE-2020-29227, have emerged and were continuously being exploited in the wild as of late 2020 to early 2021.
This blog provides details of the newly observed exploits as well as a dive deep into the exploitation analysis, vendor analysis, attack origin, and attack category distribution.
Palo Alto Networks Next-Generation Firewall customers are protected from these attacks with the URL Filtering an
Unit42
Network Attack Trends: Internet of Threats (November 2020-January 2021)
blogs_unit42·2021-04-12·CVSS 7.5
[HIGH] Network Attack Trends: Internet of Threats (November 2020-January 2021)
Threat Research Center
Trend Reports
Vulnerabilities
## Network Attack Trends: Internet of Threats (November 2020-January 2021)
Lei Xu
Yue Guan
Vaibhav Singhal
Published: April 12, 2021
Malware
Trend Reports
Vulnerabilities
Botnet
DDoS
Exploit kit
IoT
Network security trends
## Executive Summary
Unit 42 researchers analyzed network attack trends over Winter 2020 and discovered many interesting exploits in the wild. During the period of Nov. 2020 to Jan. 2021, the majority of the attacks we observed were classified as critical (75%), compared to the 50.4% we reported in the fall of 2020 . Several newly observed exploits, including CVE-2020-28188 , CVE-2020-17519 , and CVE-2020-29227 , have emerged and were continuously being exploited in the wild as of late 2020 to earl
http://packetstormsecurity.com/files/158904/D-Link-Central-WiFi-Manager-CWM-100-Remote-Code-Execution.htmlhttps://github.com/unh3x/unh3x.github.io/blob/master/_posts/2019-02-21-D-link-%28CWM-100%29-Multiple-Vulnerabilities.mdhttps://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10117https://unh3x.github.io/2019/02/21/D-link-%28CWM-100%29-Multiple-Vulnerabilities/http://packetstormsecurity.com/files/158904/D-Link-Central-WiFi-Manager-CWM-100-Remote-Code-Execution.htmlhttps://github.com/unh3x/unh3x.github.io/blob/master/_posts/2019-02-21-D-link-%28CWM-100%29-Multiple-Vulnerabilities.mdhttps://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10117https://unh3x.github.io/2019/02/21/D-link-%28CWM-100%29-Multiple-Vulnerabilities/
2019-07-06
Published
Exploited in the wild