CVE-2019-20500: D-Link DWL-2600AP Access Point Command Injection Vulnerability
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=configsave configBackup or downloadServerip parameter.
Other sources
D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=configsave configBackup or downloadServerip parameter.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For D-Link DWL-2600AP Access Point, discontinue use of the device or the affected Save Configuration functionality in the Web interface if vendor updates are unavailable.
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-20500.
What is the title of the vulnerability?
The title of the vulnerability is D-Link DWL-2600AP Access Point Command Injection Vulnerability.
What is the description of the vulnerability?
The D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.
Which software is affected by this vulnerability?
The D-Link DWL-2600AP access point is affected by this vulnerability.
Are there any references available for this vulnerability?
Yes, you can find more information about this vulnerability in the D-Link support announcement at https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10113