CVE-2018-5371: D-Link DSL-2540u Firmware
High severity, CVSS 8.8. EPSS: 42% chance of exploitation in the next 30 days.
diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.
Affected products
- D-Link DSL-2540u Firmware: version me_1.00 only
- D-Link DSL-2640u Firmware: version im_1.00 only; version me_1.00 only
Published 2018-01-12. Last modified 2026-06-17.