CVE-2018-25120 describes a critical command injection vulnerability in D-Link DNS-343 ShareCenter devices running firmware versions up to 1.05. The flaw exists in the Mail Test functionality, where the web maintenance script improperly validates user input before passing it to a system email utility. This vulnerability carries a CVSS score of 9.8 (Critical), indicating it can be exploited remotely by an unauthenticated attacker with low complexity, leading to arbitrary shell command execution as root. The potential impact includes complete compromise of confidentiality, integrity, and availability of the device. While the DNS-343 product line is End-of-Life and there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.5CPE matchmatch criteria | cpe:2.3:o:dlink:dns-343_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.