VYPR
Unrated severityNVD Advisory· Published Jun 10, 2019· Updated Aug 4, 2024

CVE-2019-12786

CVE-2019-12786

Description

An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A command injection vulnerability in D-Link DIR-818LW devices allows remote attackers to execute arbitrary commands via a crafted HNAP1 request.

Vulnerability

A command injection vulnerability exists in the HNAP1 SetWanSettings action on D-Link DIR-818LW devices running firmware versions from 2.05.B03 to 2.06B01 BETA [1]. The flaw is triggered by an XML injection of the IPAddress key, allowing an attacker to inject arbitrary commands into the system call that processes the input [1].

Exploitation

An attacker can exploit this vulnerability by sending a specially crafted HNAP1 SOAP request to the affected device on port 80 or 443, without requiring authentication [1]. The attacker needs network access to the device's web interface. The attack involves injecting a command string into the IPAddress field within the XML payload of the SetWanSettings action [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands with root privileges on the device [1]. This can lead to full compromise of the device, including unauthorized access, modification of settings, data exfiltration, and potentially using the device as a pivot for further attacks on the internal network.

Mitigation

D-Link has not released a firmware fix for this vulnerability for the DIR-818LW [1]. Users are advised to replace the device with a supported model or, if possible, restrict network access to the device's management interface and monitor for suspicious activity [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-Link/DIR-818LWdescription
  • Dlink/DIR-818LWllm-fuzzy
    Range: >=2.05.B03, <=2.06B01 BETA

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.