CVE-2018-18441 is an unauthenticated information disclosure vulnerability affecting multiple D-Link DCS series Wi-Fi cameras across numerous models and firmware versions beginning at 1.00 and above. The issue is exposed through the web-accessible endpoint /common/info.cgi, which can be requested remotely without authentication. Accessing this CGI resource returns device configuration information, including model, product, brand, firmware version, build, hardware version, device name, location, MAC address, IP address, gateway IP address, wireless status, input/output settings, speaker configuration, and sensor settings. The flaw stems from missing access control on a sensitive configuration interface, allowing remote parties to retrieve internal device and network information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept exploit for CVE-2018-18441, a vulnerability affecting D-Link DCS series Wi-Fi cameras. The main exploit file, 'cve-2018-18441.php', is a PHP script that allows a user to scan one or more target cameras for the vulnerability. The script can take a single target URL or a file containing multiple targets. For each target, it attempts to access the '/common/info.cgi' endpoint without authentication, exploiting the vulnerability to retrieve and display sensitive information from the camera. The repository also includes a README with usage instructions and a LICENSE file. The exploit is straightforward, does not include a customizable payload, and is intended for educational or testing purposes. The attack vector is network-based, requiring access to the camera's web interface.
This repository contains a proof-of-concept exploit for CVE-2018-18441, targeting D-Link DCS series Wi-Fi cameras. The exploit is implemented in a single PHP script (cve-2018-18441.php) that can scan either a single target or a list of targets provided in a file. The script sends an unauthenticated HTTP GET request to the /common/info.cgi endpoint on the target device, which, if vulnerable, returns sensitive configuration information. The README provides background on the vulnerability, affected models, and usage instructions. The exploit does not require authentication and leverages a network-based attack vector. No hardcoded IPs or domains are present; the user supplies targets via command line. The repository is structured simply, with a license, a README, and the exploit script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.