CVE-2019-15526: OS Command Injection
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings, a related issue to CVE-2019-13482.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15526?
CVE-2019-15526 is a vulnerability discovered on D-Link DIR-823G devices with firmware V1.0.2B05 that allows command injection via shell metacharacters in the Type field to SetWanSettings.
How severe is CVE-2019-15526?
CVE-2019-15526 has a severity rating of 8.8 (Critical).
What is the affected software and version of CVE-2019-15526?
The affected software is D-Link DIR-823G devices with firmware V1.0.2B05.
How can the CVE-2019-15526 vulnerability be exploited?
CVE-2019-15526 can be exploited with authentication by using shell metacharacters in the Type field to SetWanSettings via HNAP1.
Is there any fix or patch available for CVE-2019-15526?
As of now, there is no official fix or patch available for CVE-2019-15526. It is recommended to update the firmware of affected devices if a patch becomes available.