First published: Fri Aug 23 2019(Updated: )
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to Login.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-823g Firmware | =1.0.2b05 | |
Dlink Dir-823g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-15529.
The severity of CVE-2019-15529 is critical with a score of 8.8.
The affected software and version for CVE-2019-15529 is D-Link DIR-823G with firmware V1.0.2B05.
The vulnerability CVE-2019-15529 can be exploited through command injection in the Username field to Login.
Yes, authentication is required to exploit CVE-2019-15529.