CVE-2019-17621β€”D-Link DIR-859 Router Command Execution Vulnerability

PUBLISHEDvulnerability record
2023-06-29 Β· last modified June 21, 2025

Metadata

CVE ID:
CVE-2019-17621
Project:
D-Link
Product:
DIR-859 Router
Date Added:
2023-06-29
Due Date:
2023-07-20
Last Updated:
June 21, 2025

Vulnerability Name

D-Link DIR-859 Router Command Execution Vulnerability

Description

D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
Unknown

Action

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

Additional Notes

Related Weaknesses