← Vulnerability feed

Vulnerability record · CVE-2018-19300 · published 11 April 2019

CVE-2018-19300: D-Link DWR/DAP routers EXCU_SHELL header flaw allows root command execution

D Link · Dap 1530 Firmware

Multiple D-Link DWR and DAP router models ship an EXCU_SHELL file in the web directory that processes specially crafted HTTP headers. A remote unauthenticated attacker can send a GET request to /EXCU_SHELL and execute arbitrary shell commands as root. The flaw affects a broad set of consumer and small-business routers, and the vendor notes other devices may also be affected.

9.8 CVSS 3.0 Critical EPSS 74% · top 0.5% CWE-20 · Improper input validation
9.8CVSS 3.0 base score, v2 10.0
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote root command execution with a critical CVSS score, high EPSS, and public exploit references makes this an urgent patch-or-isolate case.

What it is

Multiple D-Link DWR and DAP router models ship an EXCU_SHELL file in the web directory that processes specially crafted HTTP headers. A remote unauthenticated attacker can send a GET request to /EXCU_SHELL and execute arbitrary shell commands as root. The flaw affects a broad set of consumer and small-business routers, and the vendor notes other devices may also be affected.

Impact

An attacker gains root-level command execution on the device, allowing full control of the router, interception or redirection of traffic, and use of the device as a foothold into the internal network.

Attack surface

Reachable over the network via HTTP GET to the /EXCU_SHELL URI with crafted headers; the CVSS vector indicates no authentication and no user interaction are required. Exposure depends on whether the device web interface is reachable from the attacker's position.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.743, 99.5th percentile) and references carry an Exploit tag, indicating public exploit material exists.

What to do

  • Update each affected model to the fixed firmware listed in the vendor advisory (DAP-1530/DAP-1610 1.06b01, DWR-111 1.02v02, DWR-116 1.06b03, DWR-512 2.02b01, DWR-712 2.04b01, DWR-921 A1 1.02b01 / B1 2.03b01); DWR-711 has no fixed version stated, so replace or isolate it.
  • Disable remote management and block access to the router web interface from untrusted networks (WAN and guest networks).
  • Restrict administrative access to a trusted management VLAN or specific source addresses.
  • If patching is not possible, retire or replace end-of-support devices and monitor them as untrusted.
  • Review router logs and configurations for signs of tampering after exposure.

Detection

  • Search web or proxy logs for GET requests to the /EXCU_SHELL URI.
  • Alert on requests to /EXCU_SHELL carrying unusual or malformed headers.
  • Monitor router outbound traffic for unexpected connections or DNS changes that could indicate compromise.
  • Check device firmware versions against the fixed releases and flag any that are older.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-19300 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-10824Dlink dwr-116 firmware path traversal vulnerabilityAn issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR…EPSS 12%8.8CVE-2018-10823D-Link DWR router chkisg.htm Sip parameter OS command injectionD-Link DWR-116, DWR-512, DWR-712, DWR-912, DWR-921 and DWR-111 routers fail to sanitize the Sip parameter on the chkisg.htm page, allowing shell comm…EPSS 78%analysed7.5CVE-2018-10822Dlink dwr-116 firmware path traversal vulnerabilityDirectory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through …EPSS 39%9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed10.0CVE-2026-34910Ubiquiti UniFi OS input validation flaw allows command injectionUniFi OS devices contain an improper input validation vulnerability (CWE-20) that lets a network-reachable attacker inject and execute commands. It a…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2018-19300), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.