CVE-2019-20215
CRITICALD-Link DIR-859 1.05 and 1.06B01 - Unauthenticated OS Command Injection via M-SEARCH Method
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2019-20215.
PoCs published by Metasploit, s1kr10s, secenv, including Metasploit module exploits/linux/upnp/dlink_dir859_exec_ssdpcgi.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated remote command execution vulnerability in D-Link devices via the ssdpcgi service by injecting commands into the URN or UUID headers of an M-SEARCH UDP request.
Description
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTTP_ST is mishandled. The value of the urn: service/device is checked with the strstr function, which allows an attacker to concatenate arbitrary commands separated by shell metacharacters.
Exploits (2)
This Metasploit module exploits an unauthenticated remote command execution vulnerability in D-Link devices via the ssdpcgi service by injecting commands into the URN or UUID headers of an M-SEARCH UDP request.
This Metasploit module exploits an unauthenticated remote command execution vulnerability in D-Link devices via the ssdpcgi service. It leverages command injection through malformed URN or UUID headers in UPnP M-SEARCH requests.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H