← back
CVE-2019-13372observed exploitation

CVE-2019-13372

62Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 82%
from disclosure to weapon3 days
Published on NVDJul 6
metasploit+3d
VulnCheck+646d
exploitation probability
82%top 1% of all CVEs
observed exploitation
yesVulnCheck
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.
Affected products
n/a · n/a