EXPOSURES › CVE-2018-6530
CVE-2018-6530
CRITICAL ⌖ ON CISA KEV · EXPLOITEDD-Link routers suffer from an actively exploited OS command injection flaw that allows remote code execution.
D-Link routers contain an OS command injection vulnerability that enables remote code execution, now actively exploited in the wild. This failure is critical for DIB organizations because it represents a severe supply chain and network exposure where attackers can execute arbitrary commands, bypassing standard network defenses. Organizations must ensure all D-Link networking hardware is patched or replaced immediately to prevent compromise and maintain CMMC compliance.
Shame score — The vulnerability is actively exploited in the wild, linked to ransomware, and stems from a critically poor security track record of unpatched RCEs in D-Link firmware.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.