CVE-2018-6530
KEV ransomware PoC massUnauthenticated OS Command Injection in D-Link DIR-860L/865L/868L/880L Routers
CISA: D-Link Multiple Routers OS Command Injection Vulnerability
CVE-2018-6530 is an unauthenticated OS command injection flaw (CWE-78) in the SOAP interface (soap.cgi, handled by soapcgi_main in the cgibin binary) of several D-Link routers. A remote attacker sends a crafted request to soap.cgi containing a malicious 'service' parameter, causing arbitrary OS commands to execute on the router with no credentials or user interaction required. Successful exploitation yields full command execution on the device, enabling takeover, credential theft, or recruitment into botnets. Affected users are anyone running a D-Link DIR-860L, DIR-865L, DIR-868L, or DIR-880L on firmware at or below the versions listed in the advisory. Exploitation is active in the wild: CISA added the flaw to the KEV catalog on 2022-09-08 with known ransomware use, the Mirai variant MooBot/Moobot has been exploiting vulnerable D-Link routers to build botnets, and EPSS assigns a 96.7% probability of exploitation within 30 days (100th percentile).
What to do: Apply the latest available firmware from D-Link — the vendor advisory states that the fix released under CVE-2018-20114 properly patches this vulnerability. Because all four affected models have reached end-of-life, CISA recommends disconnecting any affected device still in use if no supported firmware is available, and replacing it if it is internet-facing. As an interim mitigation, block or restrict WAN access to the router's web/SOAP (soap.cgi/HNAP) interface and check device logs for unexpected outbound connections indicative of MooBot/Mirai compromise.
| D-Link DIR-880L firmware | DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and all previous versions |
| D-Link DIR-868L firmware | DIR868LA1_FW112b04 and all previous versions |
| D-Link DIR-865L firmware | DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and all previous versions |
| D-Link DIR-860L firmware | DIR860LA1_FW110b04 and all previous versions |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.
- Affected
- D-Link Multiple Routers
- Required action
- The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.
- Due date
- Ransomware use
- Known
- Vendors
- dlink
- Products
- dir-860l firmware, dir-865l firmware, dir-868l firmware, dir-880l firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news4 stories
Mirai Variant MooBot Targeting D
Unit 42 observed the MooBot Mirai variant exploiting four D-Link vulnerabilities to compromise unpatched routers for use in DDoS attacks.
Unit 42 captured attacks exploiting four D-Link remote code execution vulnerabilities: CVE-2015-2051, CVE-2018-6530, CVE-2022-26258, and CVE-2022-28958, with three rated critical at CVSS 9.8. The exploits download the MooBot malware, a Mirai botnet variant, from infrastructure at 159.203.15.179 via wget. Compromised devices fall under full attacker control and can be used for distributed denial-of-service attacks. D-Link has published bulletins for all four flaws, but unpatched devices remain exposed.