← Back to browse · API

CVE-2018-25120

Severity
CRITICAL
CVSS
9.3
EPSS
0.09806
Risk score
40.63
CISA KEV
No
PoC
No
Published
2025-10-29
Modified
2026-05-14
First seen
2026-08-06
Aliases
CNVD-2026-10640, EUVD-2018-21606, GHSA-3R6W-F62X-HC2H
Products
D-Link DNS-343 ShareCenter <=1.05, D-Link:DNS-343 ShareCenter 0 ≤1.05
Sources
cnvd CNVD-2026-10640
euvd EUVD-2018-21606

Description

D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulnerability in the Mail Test functionality. The web maintenance script posts to the internal goForm endpoint '/goform/Mail_Test' and uses several form parameters directly in a call to a system email utility without proper input validation. An unauthenticated remote attacker can supply crafted form data that injects shell commands, resulting in execution as root on the device. NOTE: The DNS-343 product line has been declared end-of-life.

References