CVE-2018-5371

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
12/01/2018
Last modified:
14/02/2024

Description

diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:d-link:dsl-2540u_firmware:me_1.00:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dsl-2540u:-:*:*:*:*:*:*:*
cpe:2.3:o:d-link:dsl-2640u_firmware:im_1.00:*:*:*:*:*:*:*
cpe:2.3:o:d-link:dsl-2640u_firmware:me_1.00:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dsl-2640u:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools