CVE-2019-15530: OS Command Injection
Published Aug 23, 2019
·Updated
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field to Login.
Affected Software
2 affected components
Dlink Dir-823g Firmware=1.0.2b05
Dlink Dir-823g
Event History
Aug 23, 2019
CVE Published
via MITRE·04:03 PM
Data Sourced
via MITRE·04:03 PM
Description
Frequently Asked Questions
1
What is CVE-2019-15530?
CVE-2019-15530 is a vulnerability discovered on D-Link DIR-823G devices with firmware V1.0.2B05.
2
How severe is CVE-2019-15530?
CVE-2019-15530 has a severity rating of 8.8 (critical).
3
How does CVE-2019-15530 affect D-Link DIR-823G devices?
CVE-2019-15530 allows for command injection in HNAP1 via shell metacharacters in the LoginPassword field to Login.
4
What is the affected software and version for CVE-2019-15530?
The affected software is D-Link DIR-823G with firmware version 1.0.2B05.
5
Is there a fix for CVE-2019-15530?
At the moment, there is no known fix for CVE-2019-15530. It is recommended to contact the vendor for further information.