Loading
On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is sent directly to the "system" library function.
Use CWE-78, D-Link vendor hub and Dir-823g Firmware product page to widen CVE-2018-17787 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-7297, CVE-2018-17881 and CVE-2018-17786 for nearby disclosures in the same product family.