← Back

CVE-2019-17621

nvd nist
Published: Dec 30, 2019Modified: Nov 7, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

Affected (21)

14 products
Dir 859 Firmware
Dir 822 Firmware
Dir 823 Firmware
Dir 865l Firmware
Dir 868l Firmware
Dir 869 Firmware
Dir 880l Firmware
Dir 890l Firmware
Dir 890r Firmware
Dir 885l Firmware
Dir 885r Firmware
Dir 895l Firmware
Dir 895r Firmware
Dir 818lx Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Dlink
Up to 1.05b03
Version 1.06b01 beta1
Running on/withPlatform Versions
Dlink
Dir 859
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.03b01
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.12b04
Running on/withPlatform Versions
Dlink
Dir 822
All versions
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Dlink
Up to 1.00b06
Version 1.00b06 beta
Running on/withPlatform Versions
Dlink
Dir 823
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.07b01
Running on/withPlatform Versions
Dlink
Dir 865l
All versions
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.12b04
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.05b02
Running on/withPlatform Versions
Dlink
Dir 868l
All versions
Configuration H
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Dlink
Up to 1.03b02
Version 1.03b02 beta02
Running on/withPlatform Versions
Dlink
Dir 869
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.08b04
Running on/withPlatform Versions
Dlink
Dir 880l
All versions
Configuration J
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Dlink
Up to 1.11b01
Version 1.11b01 beta01
Running on/withPlatform Versions
Dlink
Dir 890l
All versions
Configuration K
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Dlink
Up to 1.11b01
Version 1.11b01 beta01
Running on/withPlatform Versions
Dlink
Dir 890r
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.12b05
Running on/withPlatform Versions
Dlink
Dir 885l
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.12b05
Running on/withPlatform Versions
Dlink
Dir 885r
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.12b10
Running on/withPlatform Versions
Dlink
Dir 895l
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.12b10
Running on/withPlatform Versions
Dlink
Dir 895r
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dlink
Dir 818lx
All versions

References (15)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.