PT-2019-15883 · D Link · Dap-1860

Nguyen Van Chung

·

Publicado

2019-12-05

·

Atualizado

2020-08-24

·

CVE-2019-19597

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DAP-1860 versions prior to v1.04b03 Beta
Description The issue allows for arbitrary remote code execution as root without authentication. This is achieved via shell metacharacters within an HNAP AUTH HTTP header.
Recommendations For versions prior to v1.04b03 Beta, update to v1.04b03 Beta or later to resolve the issue.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-19597

Produtos afetados

Dap-1860