CVE-2018-19300: D-Link Dap-1530 Firmware

Critical severity, CVSS 9.8. EPSS: 74.3% chance of exploitation in the next 30 days.

On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.

Affected products

  • D-Link Dap-1530 Firmware: up to and including 1.05
  • D-Link Dap-1610 Firmware: up to and including 1.05
  • D-Link Dwr-116 Firmware: version 1.06 only
  • D-Link Dwr-711 Firmware: up to and including 1.11
  • D-Link Dwr-111 Firmware: up to and including 1.01
  • D-Link Dwr-116 Firmware: up to and including 1.05
  • D-Link Dwr-512 Firmware: up to and including 2.02
  • D-Link Dwr-712 Firmware: up to and including 2.02
  • D-Link Dwr-921 Firmware: up to and including 1.02; up to and including 2.02

Published 2019-04-11. Last modified 2026-06-17.