← Vulnerability feed

Vulnerability record · CVE-2018-19989 · published 13 May 2019

CVE-2018-19989: D-link dir-822 firmware os command injection vulnerability

D Link · Dir 822 Firmware

In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices. In the SetQoSSettings.php source code, the uplink parameter is saved in the /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth internal configuration memory without any regex checking. And in the bwc_tc_spq_start, bwc_tc_wfq_start, and bwc_tc_adb_start functions of the bwcsvcs.php source code, the data in /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth is used with the tc command without any regex checking. A vulnerable /HNAP1/SetQoSSettings XML message could have shell metacharacters in the uplink element such as the `telnetd` string.

9.8 CVSS 3.0 Critical EPSS 5.5% · top 7.4% CWE-78 · OS command injection
9.8CVSS 3.0 base score, v2 10.0
5.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices. In the SetQoSSettings.php source code, the uplink parameter is saved in the /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth internal configuration memory without any regex checking. And in the bwc_tc_spq_start, bwc_tc_wfq_start, and bwc_tc_adb_start functions of the bwcsvcs.php source code, the data in /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth is used with the tc command without any regex checking. A vulnerable /HNAP1/SetQoSSettings XML message could have shell metacharacters in the uplink element such as the `telnetd` string.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-19989 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-17621D-Link DIR-859 UPnP gena.cgi unauthenticated command injectionThe UPnP endpoint /gena.cgi on D-Link DIR-859 firmware 1.05 and 1.06B01 Beta01 fails to sanitize input in an HTTP SUBSCRIBE request, allowing OS comm…KEVEPSS 90%analysed9.8CVE-2023-51984Dlink dir-822 firmware os command injection vulnerabilityD-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attackers to execute arbitrary comm…EPSS 2.0%9.8CVE-2023-51987Dlink dir-822 firmware missing authentication for critical function vulnerabilityD-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty password…EPSS 0.92%9.8CVE-2019-6258D-link dir-822 firmware classic buffer overflow vulnerabilityD-Link DIR-822 Rev.Bx devices with firmware v.202KRb06 and older allow a buffer overflow via long MacAddress data in a /HNAP1/SetClientInfo HNAP prot…EPSS 2.6%9.8CVE-2018-19986D-link dir-818lw firmware os command injection vulnerabilityIn the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DI…EPSS 42%9.8CVE-2018-19987D-link dir-818lw firmware os command injection vulnerabilityD-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-8…EPSS 13%9.8CVE-2018-19990D-link dir-822 firmware os command injection vulnerabilityIn the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devices. In th…EPSS 5.3%9.8CVE-2018-20675Dlink dir-822 firmware improper authentication vulnerabilityD-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-8…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2018-19989), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.