CVE-2019-17621
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
- Affected products
- D-Link Dir-818Lw, D-Link Dir-822, D-Link Dir-823G, D-Link Dir-859, D-Link Dir-865L, D-Link Dir-868L, D-Link Dir-869, D-Link Dir-880L
- Dlink dir-859 Firmware
- ≤ 1.05b03, 1.06b01
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 89.6% (100th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2019-12-30
CVE-2019-17621 at NVD
8 known exploits for CVE-2019-17621
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2019-17621
Exploit for OS Command Injection in Dlink Dir-859_Firmware
Exploit for OS Command Injection in Dlink Dir-859_Firmware
Exploit for OS Command Injection in Dlink Dir-859_Firmware
Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_Platform
D-Link DIR-859 Unauthenticated Remote Command Execution Exploit
D-Link DIR-859 Unauthenticated Remote Command Execution
D-Link DIR-859 Unauthenticated Remote Command Execution