AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-19300

CRITICAL · CVSS 9.8 EPSS 74.28%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-04-11 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. Its EPSS score suggests a 74.3% probability of exploitation in the next 30 days.

CVE
CVE-2018-19300
Severity
CRITICAL
CVSS
9.8
EPSS
74.28%

Original NVD Description

On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.

Related CVEs

Other vulnerabilities affecting the same vendor(s)