Record summary

CVE-2019-20500 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit. CISA lists CVE-2019-20500 in KEV.

Description

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Jun 29, 2023 · CISA
VulnCheck KEV
Listed · Jun 22, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBD-Link DWL-2600AP - Multiple OS Command InjectionExploitDB exploitby Raki Ben HamoudaNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

References

4