HIGH
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1
Published Oct 8, 2018
8.8
HIGHCVSS 3.0
EPSS 14.22%
Description
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.
Affected products
No data.
- ≥ 1.00 · < 1.03
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://seclists.org/fulldisclosure/2018/Oct/11 mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory
- https://securityadvisories.dlink.com/announcement/publication.aspx?name=SAP10092 x_refsource_CONFIRMPatchVendor Advisory
- https://www.exploit-db.com/exploits/45533/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.secureauth.com/labs/advisories/d-link-central-wifimanager-software-controller-multiple-vulnerabilities x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2018/Oct/11 | mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory | |
| https://securityadvisories.dlink.com/announcement/publication.aspx?name=SAP10092 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://www.exploit-db.com/exploits/45533/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry | |
| https://www.secureauth.com/labs/advisories/d-link-central-wifimanager-software-controller-multiple-vulnerabilities | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 8, 2018
Updated Aug 5, 2024
Reserved Sep 24, 2018
Link CVE-2018-17442
CISA Vulnrichment
Updated n/a