CVE-2018-17442: D-Link Central Wifimanager

High severity, CVSS 8.8. EPSS: 14.2% chance of exploitation in the next 30 days.

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.

Affected products

  • D-Link Central Wifimanager: from 1.00, before 1.03 (fixed in 1.03)

Published 2018-10-08. Last modified 2026-06-17.