CVE-2019-17508
On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.
- Affected products
- D-Link Dir-850L, D-Link Dir-859
- Dlink dir-859 a3 Firmware
- = 1.06
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 15.8% (97th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2019-10-11
CVE-2019-17508 at NVD
1 known exploit for CVE-2019-17508
Proof-of-concept code and exploit modules indexed by Sploitus