CVE-2018-10823 is a critical command injection vulnerability affecting several D-Link DWR series routers, including DWR-111, DWR-116, DWR-512, DWR-712, and DWR-912. An authenticated attacker can exploit this flaw by injecting shell commands into the "Sip" parameter on the chkisg.htm page, leading to arbitrary code execution and full device control. With a CVSS score of 8.8 (HIGH) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its network-based attack vector, low attack complexity, and complete compromise potential. While not listed in the KEV catalog, public exploit code is available via ExploitDB and Nuclei templates, and it has garnered substantial community discussion and media coverage, including reports of its use in the EnemyBot DDoS botnet.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.06CPE matchmatch criteria | cpe:2.3:o:dlink:dwr-116_firmware:*:*:*:*:*:*:*:* | ||
<= 2.02CPE matchmatch criteria | cpe:2.3:o:dlink:dwr-512_firmware:*:*:*:*:*:*:*:* | ||
<= 2.02CPE matchmatch criteria | cpe:2.3:o:dlink:dwr-912_firmware:*:*:*:*:*:*:*:* | ||
<= 1.01CPE matchmatch criteria | cpe:2.3:o:dlink:dwr-111_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.