← Vulnerability feed

Vulnerability record · CVE-2018-18008 · published 21 December 2018

CVE-2018-18008: Dlink dsl-2770l firmware hard-coded credentials vulnerability

Dlink · Dsl 2770l Firmware

spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials.

9.8 CVSS 3.0 Critical EPSS 2.0% · top 20.2% CWE-798 · Hard-coded credentials
9.8CVSS 3.0 base score, v2 5.0
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2018/Dec/45 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/106344 Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2018/Dec/45 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/106344 Third Party AdvisoryVDB Entry

Track CVE-2018-18008 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-19300D-Link DWR/DAP routers EXCU_SHELL header flaw allows root command executionMultiple D-Link DWR and DAP router models ship an EXCU_SHELL file in the web directory that processes specially crafted HTTP headers. A remote unauth…EPSS 74%analysed9.8CVE-2018-18009Dlink dir-140l firmware hard-coded credentials vulnerabilitydirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials.EPSS 2.7%9.8CVE-2018-18007Dlink dsl-2770l firmware hard-coded credentials vulnerabilityatbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials.EPSS 1.9%9.8CVE-2018-10824Dlink dwr-116 firmware path traversal vulnerabilityAn issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR…EPSS 12%8.8CVE-2018-10823D-Link DWR router chkisg.htm Sip parameter OS command injectionD-Link DWR-116, DWR-512, DWR-712, DWR-912, DWR-921 and DWR-111 routers fail to sanitize the Sip parameter on the chkisg.htm page, allowing shell comm…EPSS 78%analysed7.5CVE-2018-10822Dlink dwr-116 firmware path traversal vulnerabilityDirectory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through …EPSS 39%7.5CVE-2017-6190Dlink dwr-116 firmware path traversal vulnerabilityDirectory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arb…EPSS 18%10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed

Source: NIST National Vulnerability Database (record CVE-2018-18008), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.