D-Link Vulnerability Key Information Vendor: D-Link Product: DCS5932L Version: 2.18.01 Type: Command Execution Author: Jian Peng Institution: pengjian@ile.ac.cn Vulnerability Description A Command Injection vulnerability was found in the D-Link Technology router with firmware version 2.18.01. This vulnerability allows remote attackers to execute arbitrary OS commands from a crafted request. Remote Command Execution The parameter is directly passed by the attacker in the function, allowing control over the to attack the OS. PoC Set as , and the router will execute it: Result A shell is obtained: