First published: Mon Dec 30 2019(Updated: )
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-859 | ||
All of | ||
Any of | ||
D-Link DIR-859 | <=1.05b03 | |
D-Link DIR-859 | =1.06b01-beta1 | |
D-Link DIR-859 | ||
All of | ||
D-Link DIR-822 firmware | <=2.03b01 | |
D-Link DIR-822 | ||
All of | ||
D-Link DIR-822 firmware | <=3.12b04 | |
D-Link DIR-822 | ||
All of | ||
Any of | ||
D-Link DIR-823 Firmware | <=1.00b06 | |
D-Link DIR-823 Firmware | =1.00b06-beta | |
D-Link DIR-823 Firmware | ||
All of | ||
D-Link DIR-865L Firmware | <=1.07b01 | |
D-Link DIR-865L | ||
All of | ||
D-Link DIR-868L Firmware | <=1.12b04 | |
D-Link DIR-868LW | ||
All of | ||
D-Link DIR-868L Firmware | <=2.05b02 | |
D-Link DIR-868LW | ||
All of | ||
Any of | ||
D-Link DIR-869 | <=1.03b02 | |
D-Link DIR-869 | =1.03b02-beta02 | |
D-Link DIR-869AX | ||
All of | ||
D-Link DIR-880L Firmware | <=1.08b04 | |
D-Link DIR-880L Firmware | ||
All of | ||
Any of | ||
D-Link DIR-890L Firmware | <=1.11b01 | |
D-Link DIR-890L Firmware | =1.11b01-beta01 | |
D-Link DIR-890L Firmware | ||
All of | ||
Any of | ||
D-Link DIR-890R Firmware | <=1.11b01 | |
D-Link DIR-890R Firmware | =1.11b01-beta01 | |
D-Link DIR-890R | ||
All of | ||
D-Link DIR-885L Firmware | <=1.12b05 | |
Dlink DIR-885L MFC | ||
All of | ||
D-Link DIR-885R Firmware | <=1.12b05 | |
D-Link DIR-885R | ||
All of | ||
D-Link DIR-895L Firmware | <=1.12b10 | |
D-Link DIR-895L Firmware | ||
All of | ||
D-Link DIR-895R Firmware | <=1.12b10 | |
D-Link DIR-895R | ||
All of | ||
D-Link DIR-818L Firmware | ||
D-Link DIR-818L Firmware | ||
D-Link DIR-859 | <=1.05b03 | |
D-Link DIR-859 | =1.06b01-beta1 | |
D-Link DIR-859 | ||
D-Link DIR-822 firmware | <=2.03b01 | |
D-Link DIR-822 | ||
D-Link DIR-822 firmware | <=3.12b04 | |
D-Link DIR-823 Firmware | <=1.00b06 | |
D-Link DIR-823 Firmware | =1.00b06-beta | |
D-Link DIR-823 Firmware | ||
D-Link DIR-865L Firmware | <=1.07b01 | |
D-Link DIR-865L | ||
D-Link DIR-868L Firmware | <=1.12b04 | |
D-Link DIR-868LW | ||
D-Link DIR-868L Firmware | <=2.05b02 | |
D-Link DIR-869 | <=1.03b02 | |
D-Link DIR-869 | =1.03b02-beta02 | |
D-Link DIR-869AX | ||
D-Link DIR-880L Firmware | <=1.08b04 | |
D-Link DIR-880L Firmware | ||
D-Link DIR-890L Firmware | <=1.11b01 | |
D-Link DIR-890L Firmware | =1.11b01-beta01 | |
D-Link DIR-890L Firmware | ||
D-Link DIR-890R Firmware | <=1.11b01 | |
D-Link DIR-890R Firmware | =1.11b01-beta01 | |
D-Link DIR-890R | ||
D-Link DIR-885L Firmware | <=1.12b05 | |
Dlink DIR-885L MFC | ||
D-Link DIR-885R Firmware | <=1.12b05 | |
D-Link DIR-885R | ||
D-Link DIR-895L Firmware | <=1.12b10 | |
D-Link DIR-895L Firmware | ||
D-Link DIR-895R Firmware | <=1.12b10 | |
D-Link DIR-895R | ||
D-Link DIR-818L Firmware | ||
D-Link DIR-818L Firmware |
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17621 is a command execution vulnerability in the D-Link DIR-859 Router.
CVE-2019-17621 has a severity rating of 9.8, which is considered critical.
The CVE-2019-17621 vulnerability allows an unauthenticated remote attacker to execute system commands as root on the D-Link DIR-859 Router.
No, other versions of the D-Link firmware may also be affected by the CVE-2019-17621 vulnerability.
To fix the CVE-2019-17621 vulnerability, you should update your D-Link DIR-859 Router firmware to the latest version available.