Description
An issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls system() without checking the parameter that can be controlled by user, and finally allows remote attackers to execute arbitrary shell commands with a special HTTP header.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 09 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Jan 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-09T17:39:00.233Z
Reserved: 2019-04-05T00:00:00.000Z
Link: CVE-2019-10891
Updated: 2024-08-04T22:40:15.035Z
Status : Modified
Published: 2019-09-06T20:15:11.003
Modified: 2025-01-09T18:15:23.760
Link: CVE-2019-10891
No data.
OpenCVE Enrichment
No data.
Weaknesses