CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2019-17621

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score28.0590%
EPSS Percentile91.27th
Published2019年12月30日
Last Modified2025年11月7日

Vulnerability Description

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

Affected Platforms (CPE)

💻
Dlink

Dir 859 Firmware

<= 1.05b03
💻
Dlink

Dir 859 Firmware

= 1.06b01
💻
Dlink

Dir 822 Firmware

<= 2.03b01
💻
Dlink

Dir 822 Firmware

<= 3.12b04
💻
Dlink

Dir 823 Firmware

<= 1.00b06
💻
Dlink

Dir 823 Firmware

= 1.00b06
💻
Dlink

Dir 865l Firmware

<= 1.07b01
💻
Dlink

Dir 868l Firmware

<= 1.12b04
💻
Dlink

Dir 868l Firmware

<= 2.05b02
💻
Dlink

Dir 869 Firmware

<= 1.03b02
💻
Dlink

Dir 869 Firmware

= 1.03b02
💻
Dlink

Dir 880l Firmware

<= 1.08b04
💻
Dlink

Dir 890l Firmware

<= 1.11b01
💻
Dlink

Dir 890l Firmware

= 1.11b01
💻
Dlink

Dir 890r Firmware

<= 1.11b01
💻
Dlink

Dir 890r Firmware

= 1.11b01
💻
Dlink

Dir 885l Firmware

<= 1.12b05
💻
Dlink

Dir 885r Firmware

<= 1.12b05
💻
Dlink

Dir 895l Firmware

<= 1.12b10
💻
Dlink

Dir 895r Firmware

<= 1.12b10
💻
Dlink

Dir 818lx Firmware

All versions

References & Advisories

相關漏洞威脅