Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2019-17621

D-Link | DIR-859 RouterAdded 2023-06-29Remediation Deadline 2023-07-20

D-Link DIR-859 Router Command Execution Vulnerability

D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

Required Action

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

Weakness Classification

CWE-78

References