Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

D-Link DIR-818LW OS Command Injection Vulnerability

Vulnerability

A critical OS command injection vulnerability has been identified in the D-Link DIR-818LW router, specifically in versions released prior to December 15, 2019. The issue arises in the 'System Time Page' component, where the 'NTP Server' parameter can be manipulated to inject malicious payloads. This vulnerability can be exploited remotely, allowing for the execution of arbitrary commands on the device.

Impact

Exploitation of this vulnerability allows for OS command injection, where an attacker can execute arbitrary commands on the router's operating system. This could potentially lead to unauthorized access or control over the device.

Reproduction

To reproduce this vulnerability, access the D-Link DIR-818LW router's web interface and navigate to the 'Management' section, then select 'System Time'. In the 'NTP Server' field, inject a payload designed to exploit the command injection vulnerability. Once the payload is executed, it can be used to run arbitrary commands on the router, such as downloading a script to the device and executing it, thereby achieving a reverse shell.

Added: Jul 14, 2025, 12:17 AM
Updated: Jul 14, 2025, 12:17 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
10.0
exploitability
6.6
remediation
0.0
relevance
0.3
threat
8.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.