An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP code by uploading any file in the web root directory and then accessing it via a request.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:47:04.562Z
Reserved: 2018-09-24T00:00:00.000Z
Link: CVE-2018-17440
No data.
Status : Modified
Published: 2018-10-08T16:29:01.633
Modified: 2024-11-21T03:54:25.167
Link: CVE-2018-17440
No data.
OpenCVE Enrichment
No data.
Weaknesses