CISA Known Exploited Vulnerability

CVE-2018-6530 Ransomware

D-Link · Multiple Routers

D-Link Multiple Routers OS Command Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Known

CISA description

Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.

Required action

The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.