An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T13:30:22.971Z

Reserved: 2020-07-22T00:00:00

Link: CVE-2020-15893

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-22T19:15:12.553

Modified: 2024-11-21T05:06:23.640

Link: CVE-2020-15893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses