VYPR
Unrated severityNVD Advisory· Published Jul 10, 2019· Updated Aug 4, 2024

CVE-2019-13481

CVE-2019-13481

Description

An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MTU field to SetWanSettings.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Command injection in HNAP1 on D-Link DIR-818LW firmware 2.06betab01 via MTU parameter allows authenticated remote code execution.

Vulnerability

A command injection vulnerability exists in the HNAP1 interface of D-Link DIR-818LW devices running firmware version 2.06betab01. The flaw is triggered by injecting shell metacharacters into the MTU field of the SetWanSettings action. The vulnerable code path is reachable only after authentication to the web management interface [1].

Exploitation

An attacker must first authenticate to the device's HNAP1 service using valid credentials. Once authenticated, a crafted HTTP request to SetWanSettings with shell metacharacters (e.g., ;, |, ` ``) in the MTU parameter causes the payload to be executed as a system command. The proof-of-concept confirms that this injection is straightforward and requires no additional user interaction [1].

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary operating system commands on the device. This can lead to full compromise of the router, including data exfiltration, configuration alteration, and further network attacks. The privileges obtained are at the root level, as HNAP1 runs with elevated permissions.

Mitigation

As of the publication date (July 2019), no patch or firmware update has been released by D-Link to address this vulnerability. Users are advised to restrict access to the management interface to trusted networks, disable remote administration, and monitor for any official firmware updates. The device may be end-of-life, making a vendor fix unlikely [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-Link/DIR-818LWdescription
  • Dlink/DIR-818LWllm-fuzzy
    Range: = 2.06betab01

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.