CVE-2018-6530 is a critical OS command injection vulnerability in the soap.cgi component of several D-Link DIR series routers, including the DIR-880L, DIR-868L, DIR-865L, and DIR-860L. This flaw allows unauthenticated remote attackers to execute arbitrary operating system commands by manipulating the "service" parameter. With a CVSS score of 9.8 (Critical), it poses a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited, listed in CISA's KEV catalog, and has been associated with ransomware campaigns and the Moobot botnet, indicating widespread and ongoing threat actor interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.10b04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-860l_firmware:*:*:*:*:*:*:*:* | ||
<= 1.08b01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-865l_firmware:*:*:*:*:*:*:*:* | ||
<= 1.12b04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-868l_firmware:*:*:*:*:*:*:*:* | ||
<= 1.08b04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-880l_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.