CVE-2019-15527

HIGH

Dlink Dir-823g Firmware - OS Command Injection

Title source: rule
STIX 2.1

Description

An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to SetWanSettings.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0359
EPSS Percentile 87.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
dlink/dir-823g_firmware 1.0.2b05
Published Aug 23, 2019
Tracked Since Feb 18, 2026