← Back to CVE List
Vulnerability Intelligence Report
D-Link DIR-859 Router Command Execution Vulnerability

CVE-2019-17621

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:89.62%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
dlink dir-859_firmware 1.06b01
dlink dir-859 all
dlink dir-822_firmware all
dlink dir-822 all
dlink dir-823_firmware 1.00b06
dlink dir-823 all
dlink dir-865l_firmware all
dlink dir-865l all
dlink dir-868l_firmware all
dlink dir-868l all
dlink dir-869_firmware 1.03b02
dlink dir-869 all
dlink dir-880l_firmware all
dlink dir-880l all
dlink dir-890l_firmware 1.11b01
dlink dir-890l all
dlink dir-890r_firmware 1.11b01
dlink dir-890r all
dlink dir-885l_firmware all
dlink dir-885l all
dlink dir-885r_firmware all
dlink dir-885r all
dlink dir-895l_firmware all
dlink dir-895l all
dlink dir-895r_firmware all
dlink dir-895r all
dlink dir-818lx_firmware all
dlink dir-818lx all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
89.624%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-10-16T00:00:00
Published2019-12-30T16:09:17
Last Updated2025-10-21T23:35:54

LINK COPIED TO CLIPBOARD