CVE-2019-17621: D-Link DIR-859 Router Command Execution Vulnerability
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
Other sources
D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DIR-859 Wi-Fi routerto a version that resolves this vulnerability.Fixed in 1.05 - Upgrade
Upgrade
D-Link DIR-859 Wi-Fi routerto a version that resolves this vulnerability.Fixed in 1.06B01 Beta01 - Compensating control
If vendor updates are unavailable, discontinue use of the affected D-Link DIR-859 Wi-Fi router or stop exposing it to the local network where an unauthenticated remote attacker could reach the UPnP service at /gena.cgi.
Event History
Frequently Asked Questions
What is CVE-2019-17621?
CVE-2019-17621 is a command execution vulnerability in the D-Link DIR-859 Router.
What is the severity of CVE-2019-17621?
CVE-2019-17621 has a severity rating of 9.8, which is considered critical.
How does the CVE-2019-17621 vulnerability affect D-Link DIR-859 Router?
The CVE-2019-17621 vulnerability allows an unauthenticated remote attacker to execute system commands as root on the D-Link DIR-859 Router.
Is D-Link DIR-859 Router the only affected software?
No, other versions of the D-Link firmware may also be affected by the CVE-2019-17621 vulnerability.
How can I fix the CVE-2019-17621 vulnerability?
To fix the CVE-2019-17621 vulnerability, you should update your D-Link DIR-859 Router firmware to the latest version available.