Command Injection Vulnerability in D-Link DIR-878 Devices
CVE-2019-8318
8.8HIGH
What is CVE-2019-8318?
A command injection vulnerability exists in D-Link DIR-878 devices running firmware version 1.12A1. This security issue enables remote attackers to execute arbitrary commands by sending a specially crafted HNAP1 POST request. The vulnerability arises from improper handling of untrusted input in the SetSysEmailSettings API function, specifically within the SMTPServerPort field. Exploitation of this flaw allows attackers to gain unauthorized access, executing code with elevated privileges and potentially compromising the entire system.