CVE-2019-7297
A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request. This occurs when the GetNetworkTomographyResult function calls the system function with an untrusted input parameter named Address. Consequently, an attacker can execute any command remotely when they control this input.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 12.46% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- d-link/dir-823g firmware
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/106815Third Party Advisory
- https://github.com/leonW7/D-Link/blob/master/Vul_1.mdExploit, Third Party Advisory
- http://www.securityfocus.com/bid/106815Third Party Advisory
- https://github.com/leonW7/D-Link/blob/master/Vul_1.mdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.