First published: Fri Aug 23 2019(Updated: )
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings, a related issue to CVE-2019-13482.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-823g Firmware | =1.0.2b05 | |
Dlink Dir-823g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15526 is a vulnerability discovered on D-Link DIR-823G devices with firmware V1.0.2B05 that allows command injection via shell metacharacters in the Type field to SetWanSettings.
CVE-2019-15526 has a severity rating of 8.8 (Critical).
The affected software is D-Link DIR-823G devices with firmware V1.0.2B05.
CVE-2019-15526 can be exploited with authentication by using shell metacharacters in the Type field to SetWanSettings via HNAP1.
As of now, there is no official fix or patch available for CVE-2019-15526. It is recommended to update the firmware of affected devices if a patch becomes available.