PT-2020-5981 · D Link · D-Link Dir-816L

Published

2020-07-22

·

Updated

2023-11-08

·

CVE-2020-15893

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-816L versions 2.x before 1.10b04Beta02
Description An issue exists in the Universal Plug and Play (UPnP) component of the D-Link DIR-816L device, where UPnP is enabled by default on port 1900. This allows an attacker to perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. The vulnerability can be exploited by a remote attacker to execute arbitrary commands.
Recommendations For D-Link DIR-816L versions 2.x before 1.10b04Beta02, update to version 1.10b04Beta02 or later to resolve the issue. As a temporary workaround, consider disabling the UPnP feature on port 1900 to minimize the risk of exploitation. Restrict access to the SSDP M-SEARCH discover packet to prevent command injection attacks. Avoid using the Search Target (ST) field in the SSDP M-SEARCH packet until the issue is resolved.

Exploit

Fix

XSS

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2021-02274
CVE-2020-15893

Affected Products

D-Link Dir-816L