Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-10823 PoC — 多款D-Link产品安全漏洞

Source
Associated Vulnerability
Title:多款D-Link产品安全漏洞 (CVE-2018-10823)
Description:D-Link DWR-116等都是友讯(D-Link)公司的无线路由器产品。 多款D-Link产品中存在安全漏洞。攻击者可通过向hkisg.htm页面的‘Sip’参数注入shell命令利用该漏洞执行任意代码。以下产品和版本受到影响:D-Link DWR-116 1.06及之前版本;DWR-512 2.02及之前版本;DWR-712 2.02及之前版本;DWR-912 2.02及之前版本;DWR-921 2.02及之前版本;DWR-111 1.01及之前版本。
Description
D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 device may allow an authenticated attacker to execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.
File Snapshot

id: CVE-2018-10823 info: name: D-Link Routers - Remote Command Injection author: wisnupramoedya ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.