CVE-2018-18441 is a sensitive information disclosure vulnerability affecting numerous D-Link DCS series Wi-Fi cameras, including models like the DCS-936L and DCS-8000LH, across various firmware versions. This vulnerability allows unauthenticated remote access to a configuration file via /common/info.cgi, exposing critical device details such as model, IP address, MAC address, and wireless settings. With a CVSS score of 7.5 (HIGH), it presents a significant risk due to its network-based attack vector, low complexity, and high confidentiality impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or notable community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.00CPE matchmatch criteria | cpe:2.3:o:d-link:dcs-936l_firmware:*:*:*:*:*:*:*:* | ||
>= 1.00CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-942l_firmware:*:*:*:*:*:*:*:* | ||
>= 1.00CPE matchmatch criteria | cpe:2.3:o:d-link:dcs-8000lh_firmware:*:*:*:*:*:*:*:* | ||
>= 1.00CPE matchmatch criteria | cpe:2.3:o:d-link:dcs-942lb1_firmware:*:*:*:*:*:*:*:* | ||
>= 1.00CPE matchmatch criteria | cpe:2.3:o:d-link:dcs-5222l_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.