CVE-2018-10822 is a directory traversal vulnerability in the web interface of several D-Link router models, including the DWR-116, DIR-140L, and DWR-921. This flaw, stemming from an incomplete fix for a previous vulnerability, allows unauthenticated remote attackers to read arbitrary files on affected devices by manipulating HTTP GET requests. With a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network with low attack complexity, potentially leading to significant information disclosure. While not listed on the KEV catalog, public exploit code exists (ExploitDB, Nuclei templates), and it has garnered considerable community discussion and media coverage, indicating a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.06CPE matchmatch criteria | cpe:2.3:o:dlink:dwr-116_firmware:*:*:*:*:*:*:*:* | ||
<= 1.02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-140l_firmware:*:*:*:*:*:*:*:* | ||
<= 1.02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-640l_firmware:*:*:*:*:*:*:*:* | ||
<= 2.02CPE matchmatch criteria | cpe:2.3:o:dlink:dwr-512_firmware:*:*:*:*:*:*:*:* | ||
<= 2.02CPE matchmatch criteria | cpe:2.3:o:dlink:dwr-712_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.