CVE-2018-15515: D-Link Central Wifimanager

High severity, CVSS 7.8. EPSS: 2.5% chance of exploitation in the next 30 days.

The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from the CaptivelPortal.exe subdirectory under the D-Link directory, which allows unprivileged local users to gain SYSTEM privileges.

Affected products

  • D-Link Central Wifimanager: version 1.03_r0098 only

Published 2019-01-31. Last modified 2026-06-17.