CVE-2018-19986 describes a critical command injection vulnerability in D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 routers. The vulnerability stems from insufficient input validation of the RemotePort parameter within the /HNAP1/SetRouterSettings message, allowing shell metacharacters to be injected into an iptables command. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the high EPSS and FAUCET Risk Scores indicate significant potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.05.b03CPE matchmatch criteria | cpe:2.3:o:d-link:dir-818lw_firmware:2.05.b03:*:*:*:*:*:*:* | ||
202krb06CPE matchmatch criteria | cpe:2.3:o:d-link:dir-822_firmware:202krb06:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.