Vulnerability Details CVE-2018-17787
On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is sent directly to the "system" library function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.232
EPSS Ranking 95.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-17787
-
cpe:2.3:h:dlink:dir-823g:-
-
cpe:2.3:o:d-link:dir-823g_firmware:-