CVE-2019-15528: OS Command Injection
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to SetStaticRouteSettings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15528?
The severity of CVE-2019-15528 is critical with a severity value of 8.8.
How does CVE-2019-15528 affect D-Link DIR-823G devices?
CVE-2019-15528 affects D-Link DIR-823G devices with firmware V1.0.2B05.
What is the vulnerability description of CVE-2019-15528?
CVE-2019-15528 is a command injection vulnerability in HNAP1 of D-Link DIR-823G devices with firmware V1.0.2B05, exploitable with Authentication, via shell metacharacters in the Interface field to SetStaticRouteSettings.
How can I fix CVE-2019-15528?
To fix CVE-2019-15528, update the firmware of your D-Link DIR-823G device to a version that addresses the vulnerability.
Is D-Link DIR-823G devices with firmware V1.0.2B05 vulnerable to CVE-2019-15528?
Yes, D-Link DIR-823G devices with firmware V1.0.2B05 are vulnerable to CVE-2019-15528.