CVE-2019-17621 Details
Description
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
A vulnerability allowing unauthenticated remote command execution has been identified in the D-Link DIR-859 Wi-Fi router, specifically in firmware versions 1.05 and 1.06B01 Beta01. The issue arises in the UPnP endpoint '/gena.cgi', where an attacker can execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service over the local network.
Users are advised to update their D-Link DIR-859 routers to version 1.07b03, available as a beta hotfix. Instructions for this update can be found on the D-Link support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| D-Link DIR-859 Router Command Execution Vulnerability | Jun 29, 2023 | Jul 20, 2023 | Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| dlink dir-859 firmware | <= 1.05b03 1.06b01 beta1 |
CPE
Remediation
| |
| dlink dir-859 | All versions |
CPE
Remediation
| |
| dlink dir-822 firmware | <= 2.03b01 <= 3.12b04 |
CPE
Remediation
| |
| dlink dir-822 | All versions |
CPE
Remediation
| |
| dlink dir-823 firmware | <= 1.00b06 1.00b06 beta |
CPE
Remediation
| |
| dlink dir-823 | All versions |
CPE
Remediation
| |
| dlink dir-865l firmware | <= 1.07b01 |
CPE
Remediation
| |
| dlink dir-865l | All versions |
CPE
Remediation
| |
| dlink dir-868l firmware | <= 1.12b04 <= 2.05b02 |
CPE
Remediation
| |
| dlink dir-868l | All versions |
CPE
Remediation
| |
| dlink dir-869 firmware | <= 1.03b02 1.03b02 beta02 |
CPE
Remediation
| |
| dlink dir-869 | All versions |
CPE
Remediation
| |
| dlink dir-880l firmware | <= 1.08b04 |
CPE
Remediation
| |
| dlink dir-880l | All versions |
CPE
Remediation
| |
| dlink dir-890l firmware | <= 1.11b01 1.11b01 beta01 |
CPE
Remediation
| |
| dlink dir-890l | All versions |
CPE
Remediation
| |
| dlink dir-890r firmware | <= 1.11b01 1.11b01 beta01 |
CPE
Remediation
| |
| dlink dir-890r | All versions |
CPE
Remediation
| |
| dlink dir-885l firmware | <= 1.12b05 |
CPE
Remediation
| |
| dlink dir-885l | All versions |
CPE
Remediation
| |
| dlink dir-885r firmware | <= 1.12b05 |
CPE
Remediation
| |
| dlink dir-885r | All versions |
CPE
Remediation
| |
| dlink dir-895l firmware | <= 1.12b10 |
CPE
Remediation
| |
| dlink dir-895l | All versions |
CPE
Remediation
| |
| dlink dir-895r firmware | <= 1.12b10 |
CPE
Remediation
| |
| dlink dir-895r | All versions |
CPE
Remediation
| |
| dlink dir-818lx firmware | All versions |
CPE
Remediation
| |
| dlink dir-818lx | All versions |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 7, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Apr 3, 2025 | Modified Analysis | [email protected] |
| Feb 4, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 27, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Jan 20, 2023 | Modified Analysis | [email protected] |
| Jan 22, 2020 | CVE Modified | [email protected] |
| Jan 15, 2020 | Reanalysis | [email protected] |
| Jan 8, 2020 | Initial Analysis | [email protected] |