Showing 2 vulnerabilities on this page for DIR-859 Router

Signals CISA KEV Ransomware Nuclei
D-Link vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier a

CWE-22Jan 21, 2024
CVSS5.3v3.1EPSS82.7%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

D-Link DIR-859 Router Command Execution Vulnerability

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

CWE-78Dec 30, 2019
CVSS9.8v3.1EPSS89.6%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX