VYPR
High severity8.8NVD Advisory· Published Jan 12, 2018· Updated Jun 17, 2026

CVE-2018-5371

CVE-2018-5371

Description

diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.

Affected products

5
  • cpe:2.3:o:d-link:dsl-2540u_firmware:me_1.00:*:*:*:*:*:*:*
  • cpe:2.3:o:d-link:dsl-2640u_firmware:im_1.00:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:d-link:dsl-2640u_firmware:im_1.00:*:*:*:*:*:*:*
    • cpe:2.3:o:d-link:dsl-2640u_firmware:me_1.00:*:*:*:*:*:*:*
  • Dlink/DSL-2640Ullm-create
    Range: IM_1.00, ME_1.00
  • Dlink/DSL-2540Ullm-create
    Range: ME_1.00

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.