CVE-2019-15529: OS Command Injection
Published Aug 23, 2019
·Updated
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to Login.
Affected Software
2 affected components
Dlink Dir-823g Firmware=1.0.2b05
Dlink Dir-823g
Event History
Aug 23, 2019
CVE Published
via MITRE·04:03 PM
Data Sourced
via MITRE·04:03 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-15529.
2
What is the severity of CVE-2019-15529?
The severity of CVE-2019-15529 is critical with a score of 8.8.
3
What is the affected software and version for CVE-2019-15529?
The affected software and version for CVE-2019-15529 is D-Link DIR-823G with firmware V1.0.2B05.
4
How can the vulnerability CVE-2019-15529 be exploited?
The vulnerability CVE-2019-15529 can be exploited through command injection in the Username field to Login.
5
Is authentication required to exploit CVE-2019-15529?
Yes, authentication is required to exploit CVE-2019-15529.