Back

CVE-2019-18666

CRITICAL

An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented HTTP request. Although this is the primary vulnerability, the impact depends on the firmware version. Versions 609EU through 613EUbeta were tested. Versions through 6.12b01 have weak root credentials, allowing an attacker to gain remote root access. After 6.12b01, the root credentials were changed but the telnet service can still be started without authorization.

Published: May 15, 2020 Modified: Jun 17, 2026
CWE-306

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
dlink dap-1360_revision_f_firmware *

GitHub Security Advisory GHSA-56wp-9gq8-gjg2

An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.19%

Top 13% most likely to be exploited

Threat Score 40.2 / 100

Data Sources

NVD EPSS GitHub