D-Link DIR-859 —Unauthenticated RCE... CVE-2019–17621

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# Researchers - Miguel Mendez Z. — (s1kr10s) - Pablo Pollanco — (secenv) # Technical Details - Model : DIR-859 - Firmware Version: 1.06b01 Beta01, 1.05 - Architecture: MIPS 32 bit # Vulnerability - Remote code execution (Unauthenticated, LAN) # Affected Products ![](https://images.seebug.org/1577761808051-w331s) # Vulnerability analysis The remote code execution vulnerability was found in the code used to manage UPnP requests. Below we will provide a short description of the UPnP protocol. What is UPnP? UPnP is a communication protocol between devices, within a private network. One of its key functions is to open ports autonomously and automatically, without the user having configure the router manually for each program. It is especially useful in systems used for video games, as it works dynamically and, as we said before, autonomous. Returning to the analysis, we show in broad strokes the function genacgi_main() in the binary executable /htdocs/cgibin (of the firmware files...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息