PT-2020-5981 · D Link · D-Link Dir-816L
Published
2020-07-22
·
Updated
2023-11-08
·
CVE-2020-15893
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-816L versions 2.x before 1.10b04Beta02
Description
An issue exists in the Universal Plug and Play (UPnP) component of the D-Link DIR-816L device, where UPnP is enabled by default on port 1900. This allows an attacker to perform command injection by injecting a payload into the
Search Target (ST) field of the SSDP M-SEARCH discover packet. The vulnerability can be exploited by a remote attacker to execute arbitrary commands.Recommendations
For D-Link DIR-816L versions 2.x before 1.10b04Beta02, update to version 1.10b04Beta02 or later to resolve the issue. As a temporary workaround, consider disabling the UPnP feature on port 1900 to minimize the risk of exploitation. Restrict access to the SSDP M-SEARCH discover packet to prevent command injection attacks. Avoid using the
Search Target (ST) field in the SSDP M-SEARCH packet until the issue is resolved.Exploit
Fix
XSS
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-816L