CVE-2019-12786
Description
An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A command injection vulnerability in D-Link DIR-818LW devices allows remote attackers to execute arbitrary commands via a crafted HNAP1 request.
Vulnerability
A command injection vulnerability exists in the HNAP1 SetWanSettings action on D-Link DIR-818LW devices running firmware versions from 2.05.B03 to 2.06B01 BETA [1]. The flaw is triggered by an XML injection of the IPAddress key, allowing an attacker to inject arbitrary commands into the system call that processes the input [1].
Exploitation
An attacker can exploit this vulnerability by sending a specially crafted HNAP1 SOAP request to the affected device on port 80 or 443, without requiring authentication [1]. The attacker needs network access to the device's web interface. The attack involves injecting a command string into the IPAddress field within the XML payload of the SetWanSettings action [1].
Impact
Successful exploitation allows the attacker to execute arbitrary commands with root privileges on the device [1]. This can lead to full compromise of the device, including unauthorized access, modification of settings, data exfiltration, and potentially using the device as a pivot for further attacks on the internal network.
Mitigation
D-Link has not released a firmware fix for this vulnerability for the DIR-818LW [1]. Users are advised to replace the device with a supported model or, if possible, restrict network access to the device's management interface and monitor for suspicious activity [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- D-Link/DIR-818LWdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/TeamSeri0us/pocs/blob/master/iot/dlink/dir818-protected.pdfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.