CVE-2018-17440

UnknownEPSS 36.89%

Last modified

CVE-2018-17440 is a vulnerability of currently unknown severity. An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). EPSS estimates a 36.89% chance of exploitation in the next 30 days.

Description

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP code by uploading any file in the web root directory and then accessing it via a request.

Metrics

EPSS Probability
36.89%

98.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DlinkCentral Wifimanager>= 1.00, < 1.03

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-17440?
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP code by uploading any file in the web root directory and then accessing it via a request.
How severe is CVE-2018-17440?
Severity scoring for CVE-2018-17440 is pending analysis. The EPSS model estimates a 36.89% probability of exploitation in the next 30 days.
How do I fix CVE-2018-17440?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-17440?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST