CVE-2018-6530

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
06/03/2018
Last modified:
07/11/2025

Description

OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dir-860l_firmware:*:*:*:*:*:*:*:* 1.10b04 (including)
cpe:2.3:h:dlink:dir-860l:a1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-865l_firmware:*:*:*:*:*:*:*:* 1.08b01 (including)
cpe:2.3:h:dlink:dir-865l:a1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-868l_firmware:*:*:*:*:*:*:*:* 1.12b04 (including)
cpe:2.3:h:dlink:dir-868l:a1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-880l_firmware:*:*:*:*:*:*:*:* 1.08b04 (including)
cpe:2.3:h:dlink:dir-880l:a1:*:*:*:*:*:*:*