Command Injection Vulnerability in D-Link DIR-878 Devices
CVE-2019-8318
8.8HIGH
Summary
A command injection vulnerability exists in D-Link DIR-878 devices running firmware version 1.12A1. This security issue enables remote attackers to execute arbitrary commands by sending a specially crafted HNAP1 POST request. The vulnerability arises from improper handling of untrusted input in the SetSysEmailSettings API function, specifically within the SMTPServerPort field. Exploitation of this flaw allows attackers to gain unauthorized access, executing code with elevated privileges and potentially compromising the entire system.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published