CVE-2019-20215: OS Command Injection
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTTPST is mishandled. The value of the urn: service/device is checked with the strstr function, which allows an attacker to concatenate arbitrary commands separated by shell metacharacters.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20215?
The severity of CVE-2019-20215 is critical with a CVSS score of 9.8.
How can remote attackers exploit CVE-2019-20215?
Remote attackers can exploit CVE-2019-20215 by executing arbitrary OS commands via a specific method in ssdpcgi().
Which D-Link devices are affected by CVE-2019-20215?
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices are affected by CVE-2019-20215.
Is there a fix or patch available for CVE-2019-20215?
Yes, D-Link has released firmware updates to address the vulnerability. It is recommended to update to the latest firmware version.
Where can I find more information about CVE-2019-20215?
You can find more information about CVE-2019-20215 in the references provided: [link1], [link2], [link3].