Vulnerability record · CVE-2018-10823 · published 17 October 2018
CVE-2018-10823: D-Link DWR router chkisg.htm Sip parameter OS command injection
Dlink · Dwr 116 Firmware
D-Link DWR-116, DWR-512, DWR-712, DWR-912, DWR-921 and DWR-111 routers fail to sanitize the Sip parameter on the chkisg.htm page, allowing shell command injection. An attacker who can authenticate to the device can run arbitrary commands and take full control of the router internals. The flaw is a classic OS command injection (CWE-78) with a network-reachable vector.
Description
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable authenticated command injection with public exploit code and very high EPSS, though it requires valid credentials and no KEV listing.
What it is
D-Link DWR-116, DWR-512, DWR-712, DWR-912, DWR-921 and DWR-111 routers fail to sanitize the Sip parameter on the chkisg.htm page, allowing shell command injection. An attacker who can authenticate to the device can run arbitrary commands and take full control of the router internals. The flaw is a classic OS command injection (CWE-78) with a network-reachable vector.
Impact
An authenticated attacker gains arbitrary command execution on the device, giving full control over router internals, including configuration, traffic handling and any credentials or data passing through it.
Attack surface
Reached over the network via the chkisg.htm page Sip parameter (CVSS AV:N). The vector requires low privileges (PR:L) and no user interaction (UI:N), so any valid low-privileged session is enough.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.777, 99.5th percentile) and public references are tagged Exploit, indicating working exploit code is publicly available. No ransomware association is documented.
What to do
- Apply the latest D-Link firmware for the affected DWR models; if no fixed firmware exists, replace or retire the device.
- Restrict management access to a trusted LAN or VPN and never expose the web interface to the internet.
- Change default credentials and enforce strong unique admin passwords to limit who can reach the vulnerable page.
- Monitor vendor advisories for these end-of-life models and plan hardware replacement where support has ended.
Detection
- Inspect HTTP requests to chkisg.htm for shell metacharacters or command strings in the Sip parameter.
- Alert on unexpected outbound connections or processes spawned from the router's web management service.
- Review router logs for authentication to the management interface from unusual source addresses followed by configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://sploit.tech/2018/10/12/D-Link.html | ExploitThird Party Advisory |
| https://seclists.org/fulldisclosure/2018/Oct/36 | ExploitMailing ListThird Party Advisory |
| http://sploit.tech/2018/10/12/D-Link.html | ExploitThird Party Advisory |
| https://seclists.org/fulldisclosure/2018/Oct/36 | ExploitMailing ListThird Party Advisory |
Track CVE-2018-10823 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-10823), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.