On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.
Conclusion & alert: CVE-2018-19300 is rated High Exploit Risk (94/100): CVSS Critical severity, with high exploitation likelihood (EPSS 74.28%, 99th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +50.95% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 23.33% | 74.28% | +50.95% |
| 2 | 2026-01-15 | 20.75% | 23.33% | +2.57% |
| 3 | 2025-11-21 | — | 20.75% | — |
Full EPSS history (18 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.0 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| d-link | dap-1530_firmware | <= 1.05 | cpe:2.3:o:d-link:dap-1530_firmware:*:*:*:*:*:*:*:* |
| d-link | dap-1610_firmware | <= 1.05 | cpe:2.3:o:d-link:dap-1610_firmware:*:*:*:*:*:*:*:* |
| dlink | dwr-111_firmware | <= 1.01 | cpe:2.3:o:dlink:dwr-111_firmware:*:*:*:*:*:*:*:* |
| d-link | dwr-116_firmware | 1.06 | cpe:2.3:o:d-link:dwr-116_firmware:1.06:b1:*:*:*:*:*:* |
| d-link | dwr-116_firmware | 1.06 | cpe:2.3:o:d-link:dwr-116_firmware:1.06:b2:*:*:*:*:*:* |
| dlink | dwr-116_firmware | <= 1.05 | cpe:2.3:o:dlink:dwr-116_firmware:*:*:*:*:*:*:*:* |
| dlink | dwr-512_firmware | <= 2.02 | cpe:2.3:o:dlink:dwr-512_firmware:*:*:*:*:*:*:*:* |
| d-link | dwr-711_firmware | <= 1.11 | cpe:2.3:o:d-link:dwr-711_firmware:*:*:*:*:*:*:*:* |
| dlink | dwr-712_firmware | <= 2.02 | cpe:2.3:o:dlink:dwr-712_firmware:*:*:*:*:*:*:*:* |
| dlink | dwr-921_firmware | <= 1.02 | cpe:2.3:o:dlink:dwr-921_firmware:*:*:*:*:*:*:*:* |
| dlink | dwr-921_firmware | <= 2.02 | cpe:2.3:o:dlink:dwr-921_firmware:*:*:*:*:*:*:*:* |