CVE-2019-13128: OS Command Injection
An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway field to SetStaticRouteSettings.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13128?
CVE-2019-13128 is a command injection vulnerability in D-Link DIR-823G devices with firmware 1.02B03, which can be exploited with authentication via shell metacharacters in the IPAddress or Gateway field to SetStaticRouteSettings.
How severe is CVE-2019-13128?
CVE-2019-13128 has a severity rating of 8.8, which is considered critical.
How can I check if my D-Link DIR-823G device is affected by CVE-2019-13128?
To check if your D-Link DIR-823G device is affected by CVE-2019-13128, verify that it is running firmware version 1.02B03.
How do I fix CVE-2019-13128?
To fix CVE-2019-13128, you should update your D-Link DIR-823G device firmware to a version that is not vulnerable to this command injection vulnerability.
Where can I find more information about CVE-2019-13128?
You can find more information about CVE-2019-13128 in the following reference: https://github.com/TeamSeri0us/pocs/blob/master/iot/dlink/DIR-823G-v2.pdf