The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
2019-12-30T17:15:19.857
2025-04-03T20:05:08.703
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dir-859_firmware | ≤ 1.05b03 | Yes |
Operating System | dlink | dir-859_firmware | 1.06b01 | Yes |
Hardware | dlink | dir-859 | - | No |
Operating System | dlink | dir-822_firmware | ≤ 2.03b01 | Yes |
Hardware | dlink | dir-822 | - | No |
Operating System | dlink | dir-822_firmware | ≤ 3.12b04 | Yes |
Hardware | dlink | dir-822 | - | No |
Operating System | dlink | dir-823_firmware | ≤ 1.00b06 | Yes |
Operating System | dlink | dir-823_firmware | 1.00b06 | Yes |
Hardware | dlink | dir-823 | - | No |
Operating System | dlink | dir-865l_firmware | ≤ 1.07b01 | Yes |
Hardware | dlink | dir-865l | - | No |
Operating System | dlink | dir-868l_firmware | ≤ 1.12b04 | Yes |
Hardware | dlink | dir-868l | - | No |
Operating System | dlink | dir-868l_firmware | ≤ 2.05b02 | Yes |
Hardware | dlink | dir-868l | - | No |
Operating System | dlink | dir-869_firmware | ≤ 1.03b02 | Yes |
Operating System | dlink | dir-869_firmware | 1.03b02 | Yes |
Hardware | dlink | dir-869 | - | No |
Operating System | dlink | dir-880l_firmware | ≤ 1.08b04 | Yes |
Hardware | dlink | dir-880l | - | No |
Operating System | dlink | dir-890l_firmware | ≤ 1.11b01 | Yes |
Operating System | dlink | dir-890l_firmware | 1.11b01 | Yes |
Hardware | dlink | dir-890l | - | No |
Operating System | dlink | dir-890r_firmware | ≤ 1.11b01 | Yes |
Operating System | dlink | dir-890r_firmware | 1.11b01 | Yes |
Hardware | dlink | dir-890r | - | No |
Operating System | dlink | dir-885l_firmware | ≤ 1.12b05 | Yes |
Hardware | dlink | dir-885l | - | No |
Operating System | dlink | dir-885r_firmware | ≤ 1.12b05 | Yes |
Hardware | dlink | dir-885r | - | No |
Operating System | dlink | dir-895l_firmware | ≤ 1.12b10 | Yes |
Hardware | dlink | dir-895l | - | No |
Operating System | dlink | dir-895r_firmware | ≤ 1.12b10 | Yes |
Hardware | dlink | dir-895r | - | No |
Operating System | dlink | dir-818lx_firmware | - | Yes |
Hardware | dlink | dir-818lx | - | No |