Security Advisory

CVE-2018-17787

9.8
CRITICAL

Vulnerability Description

On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is sent directly to the "system" library function.
Published Date October 2, 2018
Official Source NIST NVD Advisory