CVE-2018-17440 in D Link and D-Link Products
Published on October 8, 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP code by uploading any file in the web root directory and then accessing it via a request.
Products Associated with CVE-2018-17440
stack.watch emails you whenever new vulnerabilities are published in D Link Central Wifimanager or D-Link Central Wifimanager. Just hit a watch button to start following.
Exploit Probability
EPSS
15.18%
Percentile
94.46%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.