Dell EMC iDRAC - RCE (CVE-2018-1207)
175Exploiting IPs reported
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.
CrowdSec analysis
CVE-2018-1207 is a critical CGI injection vulnerability in Dell EMC iDRAC7 and iDRAC8 versions prior to 2.52.52.52, allowing remote unauthenticated attackers to execute arbitrary code on affected systems. This flaw could be exploited to gain full control over the device, leading to potential data breaches, system manipulation, or service disruption.
CrowdSec has been tracking this vulnerability and its exploits since 25th of September 2025.
CrowdSec network observations suggest that most exploitation of CVE-2018-1207 involves focused reconnaissance to identify viable targets. Attackers typically tailor their campaigns based on system exposure and configuration. It is unlikely that a given attack is accidental. Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2018-1207 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2018-1207 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.
Attackers exploit this vulnerability by sending crafted requests to /cgi-bin/login with the LD_DEBUG parameter, enabling remote code injection on Dell iDRAC7/8 devices.
Exploitation
Get real-time information about exploitation attempts and actors involved.
Common Weakness Enumeration (CWE)
Protection
Find out relevant information to protect your stack against this CVE.
Blocklist
With our advanced worldwide network detection, CrowdSec can provide a list of IPs known for exploiting the vulnerability.
To increase your protection against this CVE, block exploitation attempts with this list of identified actors.