CVE-2018-20114 Information
Feb 14, 2021
cve
Description
On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices unauthenticated remote OS command execution can occur in the soap.cgi service of the cgibin binary via an &&\ substring in the service parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-6530.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/pr0v3rbs/CVE/tree/master/CVE-2018-20114
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: