CVE-2018-10967: D-Link Dir-550a Firmware

High severity, CVSS 8.8. EPSS: 3.8% chance of exploitation in the next 30 days.

On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.

Affected products

  • D-Link Dir-550a Firmware: up to and including 2.10kr
  • D-Link Dir-604m Firmware: up to and including 2.10kr

Published 2018-05-18. Last modified 2026-06-17.