Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 96.7%; technical severity is CVSS 9.8.
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.
Who should care
- Teams operating Multiple Routers, Dir-860l Firmware, Dir-865l Firmware +2 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Multiple Routers, Dir-860l Firmware, Dir-865l Firmware +2 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Vendor remediation
Patch and remediation links
Use the vendor source below to confirm the correct fixed version, package or mitigation for your affected product.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-78
- Affected versions
- D-Link Multiple Routers; Dlink Dir-860l Firmware (End Including: 1.10b04); Dlink Dir-865l Firmware (End Including: 1.08b01); Dlink Dir-868l Firmware (End Including: 1.12b04); Dlink Dir-880l Firmware (End Including: 1.08b04)
- Published
- 6 March 2018
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 96.7%
- Signal calculated at 88