D-Link router OS command injection (CVE-2018-6530) — the fix was issued under another identifier, and unsupported devices are to be disconnected
An OS command injection vulnerability in home and small-office routers. The required action notes that the fix for this entry was issued under a different identifier, and directs that devices past end-of-life be disconnected if still in use.
Key facts
- CVE IDCVE-2018-6530
- Affected (vendor / product)D-Link Multiple Routers
- CWECWE-78
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2022-09-29 (U.S. federal civilian agencies, BOD 22-01)
Key points
- The affected products are multiple D-Link routers, classified as improper neutralization of special elements used in an OS command.
- The required action notes a vendor advisory stating the fix for this entry was made under a different identifier.
- Identifiers of a vulnerability and of the update fixing it do not always match, which automated matching can miss.
- Supported devices are to be updated; devices past end-of-life are to be disconnected if still in use.
- Across the records this site holds as of 2026-09-04, home and small equipment entries with known ransomware use number 13.
1Numbers that do not line up
- 1The catalog entryListed under one identifier
- 2The vendor advisoryStates the fix was made under a different identifier
- 3The catalog noteRecords that the other fix properly patches this entry
- 4What that meansSearching for a fix by this entry identifier alone finds nothing
The identifier of a vulnerability and the identifier attached to the update that fixed it do not always match. This entry is such a case, with the required action noting that a fix under another identifier properly patches it. Where matching by identifier is automated, that divergence can become an oversight.
2When support has ended
The required action divides in two: update while supported, disconnect once support has ended. Disconnection rather than updating is called for because with no fix provided there is nothing else available. This site covers another entry requiring products past end-of-service to be disconnected.
3Where home and small-office equipment sits
Equipment placed in homes and small offices is numerous, and who manages it is often unclear. It is frequently installed once, left configured as it came, and used for years without anyone learning that updates exist. That this identifier dates from 2018 while the listing came in 2022 conveys how time runs for equipment of this kind.
4Who applies the update
In a business system, someone is assigned to updating. For equipment in small sites or in homes, that assignment tends to blur. This site covers the point that asset management centred on core facilities leaves endpoint updating incomplete, and how equipment is placed changes how hard it is to defend.
Why it matters
Automated matching by identifier can miss entries whose fix was issued under another number. Equipment in small sites and homes has blurred responsibility for updating, so placement changes how hard defence becomes.
FAQ
Why do the identifiers differ?
What is required once support has ended?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).