CyberSec.Space Logo
Back to CVE Browser

CVE-2019-17621

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score28.0590%
EPSS Percentile91.27th
PublishedDec 30, 2019
Last ModifiedNov 7, 2025

Vulnerability Description

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

Affected Platforms (CPE)

πŸ’»
Dlink

Dir 859 Firmware

<= 1.05b03
πŸ’»
Dlink

Dir 859 Firmware

= 1.06b01
πŸ’»
Dlink

Dir 822 Firmware

<= 2.03b01
πŸ’»
Dlink

Dir 822 Firmware

<= 3.12b04
πŸ’»
Dlink

Dir 823 Firmware

<= 1.00b06
πŸ’»
Dlink

Dir 823 Firmware

= 1.00b06
πŸ’»
Dlink

Dir 865l Firmware

<= 1.07b01
πŸ’»
Dlink

Dir 868l Firmware

<= 1.12b04
πŸ’»
Dlink

Dir 868l Firmware

<= 2.05b02
πŸ’»
Dlink

Dir 869 Firmware

<= 1.03b02
πŸ’»
Dlink

Dir 869 Firmware

= 1.03b02
πŸ’»
Dlink

Dir 880l Firmware

<= 1.08b04
πŸ’»
Dlink

Dir 890l Firmware

<= 1.11b01
πŸ’»
Dlink

Dir 890l Firmware

= 1.11b01
πŸ’»
Dlink

Dir 890r Firmware

<= 1.11b01
πŸ’»
Dlink

Dir 890r Firmware

= 1.11b01
πŸ’»
Dlink

Dir 885l Firmware

<= 1.12b05
πŸ’»
Dlink

Dir 885r Firmware

<= 1.12b05
πŸ’»
Dlink

Dir 895l Firmware

<= 1.12b10
πŸ’»
Dlink

Dir 895r Firmware

<= 1.12b10
πŸ’»
Dlink

Dir 818lx Firmware

All versions

References & Advisories

Related Vulnerabilities