CVE-2019-17621
D-Link DIR-859 Router Command Execution Vulnerability
⚠ KEVEPSS 89.6%
Description
D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
How to fix CVE-2019-17621
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2019-17621 being exploited?
Yes — CVE-2019-17621 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.