Vulnerability record · CVE-2018-19300 · published 11 April 2019
CVE-2018-19300: D-Link DWR/DAP routers EXCU_SHELL header flaw allows root command execution
D Link · Dap 1530 Firmware
Multiple D-Link DWR and DAP router models ship an EXCU_SHELL file in the web directory that processes specially crafted HTTP headers. A remote unauthenticated attacker can send a GET request to /EXCU_SHELL and execute arbitrary shell commands as root. The flaw affects a broad set of consumer and small-business routers, and the vendor notes other devices may also be affected.
Description
On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote root command execution with a critical CVSS score, high EPSS, and public exploit references makes this an urgent patch-or-isolate case.
What it is
Multiple D-Link DWR and DAP router models ship an EXCU_SHELL file in the web directory that processes specially crafted HTTP headers. A remote unauthenticated attacker can send a GET request to /EXCU_SHELL and execute arbitrary shell commands as root. The flaw affects a broad set of consumer and small-business routers, and the vendor notes other devices may also be affected.
Impact
An attacker gains root-level command execution on the device, allowing full control of the router, interception or redirection of traffic, and use of the device as a foothold into the internal network.
Attack surface
Reachable over the network via HTTP GET to the /EXCU_SHELL URI with crafted headers; the CVSS vector indicates no authentication and no user interaction are required. Exposure depends on whether the device web interface is reachable from the attacker's position.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.743, 99.5th percentile) and references carry an Exploit tag, indicating public exploit material exists.
What to do
- Update each affected model to the fixed firmware listed in the vendor advisory (DAP-1530/DAP-1610 1.06b01, DWR-111 1.02v02, DWR-116 1.06b03, DWR-512 2.02b01, DWR-712 2.04b01, DWR-921 A1 1.02b01 / B1 2.03b01); DWR-711 has no fixed version stated, so replace or isolate it.
- Disable remote management and block access to the router web interface from untrusted networks (WAN and guest networks).
- Restrict administrative access to a trusted management VLAN or specific source addresses.
- If patching is not possible, retire or replace end-of-support devices and monitor them as untrusted.
- Review router logs and configurations for signs of tampering after exposure.
Detection
- Search web or proxy logs for GET requests to the /EXCU_SHELL URI.
- Alert on requests to /EXCU_SHELL carrying unusual or malformed headers.
- Monitor router outbound traffic for unexpected connections or DNS changes that could indicate compromise.
- Check device firmware versions against the fixed releases and flag any that are older.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-19300 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-19300), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.