Umbra Wiki cve cve/CVE-2018-6530
Back to wiki

CVE-2018-6530 — D-Link Multiple Routers OS Command Injection Vulnerability

provenance: imported · CVE: CVE-2018-6530

CVE-2018-6530: D-Link Multiple Routers OS Command Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project D-Link
Product Multiple Routers
Date added 2022-09-08
Due date 2022-09-29
Ransomware campaign use Known

Description

Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.

Required action (CISA)

The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.

Notes

https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10105; https://nvd.nist.gov/vuln/detail/CVE-2018-6530

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2018-6530
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog