Loading
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.
Use CWE-78, D-Link vendor hub and Dir-550a Firmware product page to widen CVE-2018-10967 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-10968 for nearby disclosures in the same product family.