CVE-2018-15515: D-Link Central Wifimanager
High severity, CVSS 7.8. EPSS: 2.5% chance of exploitation in the next 30 days.
The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from the CaptivelPortal.exe subdirectory under the D-Link directory, which allows unprivileged local users to gain SYSTEM privileges.
Affected products
- D-Link Central Wifimanager: version 1.03_r0098 only
Published 2019-01-31. Last modified 2026-06-17.