CVE-2019-9122
HIGHD-Link DIR-825 Rev.B 2.10 - Remote Code Execution via ntp_server Parameter
Title source: manualDescription
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/WhooAmii/whooamii.github.io/blob/master/2018/DIR-825/command%20injection.md
Scores
CVSS v3
8.8
EPSS
0.1123
EPSS Percentile
93.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
dlink/dir-825_rev.b_firmware
2.10
Published
Feb 25, 2019
Tracked Since
Feb 18, 2026