Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2019-17621

CRITICAL · 9.5 CVSS Gepubliceerd: CWE-78

Beschrijving

D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

Vendors

D-link

Affected products

Dir-859 Router

References