Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-09-27T11:34:12
Updated: 2024-08-05T01:24:48.593Z
Reserved: 2019-09-27T00:00:00
Link: CVE-2019-16920
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-09-27T12:15:10.017
Modified: 2024-11-21T04:31:20.637
Link: CVE-2019-16920
Redhat
No data.