#VU24734 OS Command Injection in DIR-859 - CVE-2019-20217
Published: January 29, 2020
DIR-859
D-Link
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to the SERVER_ID is mishandled in the "ssdpcgi()" function in "/htdocs/cgibin". A remote unauthenticated attacker can execute arbitrary OS commands on the target system via the urn: to the M-SEARCH method.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://medium.com/@s1kr10s/d-link-dir-859-rce-unauthenticated-cve-2019-20216-cve-2019-20217-en-6bca043500ae
- https://medium.com/@s1kr10s/d-link-dir-859-rce-unauthenticated-cve-2019-20216-cve-2019-20217-es-e11ca6168d35
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10147