Record summary

CVE-2019-17621 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC. CISA lists CVE-2019-17621 in KEV.

Description

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Jun 29, 2023 · CISA
VulnCheck KEV
Listed · Jun 22, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

2

Catalogued exploits

MetasploitD-Link DIR-859 Unauthenticated Remote Command ExecutionMetasploit exploitby Miguel Mendez Z., <Miguel Mendez Z., @s1kr10s> +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

Repository PoCs

GitHubs1kr10s/D-Link-DIR-859-RCERepository PoCby s1kr10sStars: 47Not analyzed13 files

1.9 MiB

GitHub

PoC details

References

11