Record summary

CVE-2019-20501 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.

Description

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.cgi?action=upgrade firmwareRestore or firmwareServerip parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBD-Link DWL-2600AP - Multiple OS Command InjectionExploitDB exploitby Raki Ben HamoudaNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

References

3