S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 23, 2024

CVE-2018-6530 Scanner

CVE-2018-6530 scanner - Remote Code Execution (RCE) vulnerability in D-Link DIR-880L

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2018-6530
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The D-Link DIR-880L is a popular wireless router used in both home and business settings. It provides high-speed wireless internet access and network connectivity to multiple devices, making it an essential tool for those who rely on the internet for work, study, entertainment and communication. The router provides remarkable features such as wireless AC connectivity, dual-band Wi-Fi, and Gigabit Ethernet ports, which makes it easier to manage your network.

However, the router has been found to have a security vulnerability known as CVE-2018-6530. This vulnerability is a command injection vulnerability that exists in soap.cgi (soap_cgi_main in cgibin). It is present in the firmware of D-Link DIR-880L, DIR-868L, DIR-865L, and DIR-860L routers. This vulnerability allows an attacker to execute arbitrary OS commands by sending a request using the service parameter.

If exploited, this vulnerability can lead to complete access to the router by an attacker, allowing them to gain control of the network. An attacker could gain access to private and confidential data, potentially stealing sensitive information such as passwords, banking details, and personal information. Moreover, an attacker could use the router as part of a Botnet to conduct further attacks or steal information from other connected networks.

Thankfully, with the pro features of the s4e.io platform, individuals and businesses can easily and quickly discover vulnerabilities in their digital assets. This platform scans for vulnerabilities, provides detailed reports, and suggests solutions to optimize security. By using its advanced capabilities, users can protect their digital assets effectively. Therefore, s4e.io is an essential tool that can help users to identify and solve security risks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Install the latest firmware updates for the affected D-Link routers.
  • Disable remote access to the router.
  • Limit access to the router to trusted sources.
  • Use complex passwords for the router login and change them regularly.
  • Monitor the router logs for any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-6530 scanner - Remote Code Execution (RCE) vulnerability in D-Link DIR-880L | S4E