CVE Database · CVE-2018-10967
CVSS v3.1
N/A
EPSS
3.83%
Published
May 18, 2018
Modified
Nov 21, 2024
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.
Weaknesses (CWE)
Affected Products (4)
References (2)