Input validation error in Central WiFiManager - CVE-2018-15515
Published: January 31, 2019 / Updated: August 8, 2020
Central WiFiManager
Detailed vulnerability description
The vulnerability allows a local authenticated user to execute arbitrary code.
The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from the CaptivelPortal.exe subdirectory under the D-Link directory, which allows unprivileged local users to gain SYSTEM privileges.