S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-10823 Scanner

CVE-2018-10823 scanner - OS Command Injection vulnerability in D-Link DWR-116, DWR-512, DWR-712, DWR-912, DWR-921 and DWR-111

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-10823
8.8
CVSS

An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The D-Link DWR-116, DWR-512, DWR-712, DWR-912, DWR-921 and DWR-111 are wireless routers that enable users to connect to the internet wirelessly. These devices are commonly used in homes, small businesses, and remote locations where the internet connection is only available through wireless signals. The routers provide stable and reliable connections with high-speed data transfer rates. They are also equipped with advanced security features that enable users to access the internet with confidence.

Recently, a critical vulnerability was discovered in these devices, identified as CVE-2018-10823. The vulnerability allows authenticated attackers to execute arbitrary code by injecting shell commands into the chkisg.htm page SIP parameter. This grants full control to the attacker and enables them to access and manipulate the device's internals, including the operating system and the applications it runs.

Exploitation of this vulnerability can lead to various adverse consequences. Attackers can carry out a range of malicious activities, such as intercepting and tampering with network traffic, stealing sensitive information, and launching further attacks on connected devices. They can also modify device settings, install malware, and take control of the network remotely without the user's knowledge.

Thanks to the pro features of the s4e.io platform, readers of this article can access comprehensive information about vulnerabilities in their digital assets quickly and easily. The platform provides real-time alerts, accurate vulnerability assessments, and customized recommendations to enhance digital security. Users can also scan and test their systems for vulnerabilities and receive detailed reports on their security posture. By taking advantage of these tools, users can stay one step ahead of cyber threats and safeguard their systems from exploitable vulnerabilities.

 

REFERENCES

Solution Advice

To protect against this vulnerability, D-Link has released firmware updates for all affected devices. It is highly recommended that users install the latest firmware versions as soon as possible. Additionally, the following precautions can help reduce the risk of exploitation:

  • Disable remote management and access to the device
  • Change default login credentials for the device's web interface
  • Enable automatic firmware updates
  • Use a strong Wi-Fi password
  • Monitor network traffic for suspicious activities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-10823 scanner - OS Command Injection vulnerability in D-Link DWR-116, DWR-512, DWR-712, DWR-912, DWR-921 and DWR-111 | S4E