CVE-2019-12786: D-Link Dir-818lw Firmware

High severity, CVSS 8.8. EPSS: 3.6% chance of exploitation in the next 30 days.

An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.

Affected products

  • D-Link Dir-818lw Firmware: version 2.05.b03 only; version 2.06b01 only

Published 2019-06-10. Last modified 2026-06-17.