• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

central_wifimanager

CVE-2018-17440

February 26, 2023 by

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP code by uploading any file in the web root directory and then accessing it via a request.

CVE-2018-17441

February 26, 2023 by

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The ‘username’ parameter of the addUser endpoint is vulnerable to stored XSS.

CVE-2018-17442

February 26, 2023 by

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.

CVE-2018-17443

February 26, 2023 by

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The ‘sitename’ parameter of the UpdateSite endpoint is vulnerable to stored XSS.

CVE-2018-15515

February 26, 2023 by

The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse “quserex.dll” from the CaptivelPortal.exe subdirectory under the D-Link directory, which allows unprivileged local users to gain SYSTEM privileges.

CVE-2018-15516

February 26, 2023 by

The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in SSRF.

  • Go to page 1
  • Go to page 2
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE