CVE-2019-19598 is an authentication bypass vulnerability affecting D-Link DAP-1860 devices running firmware versions prior to v1.04b03 Beta. An attacker can gain unauthorized access to administrator functions by manipulating the HNAP_AUTH header timestamp in HTTP requests. This vulnerability carries a CVSS v3.1 score of 8.8 (High), indicating a critical risk due to its low attack complexity, requiring no user interaction, and leading to high impacts on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for a complete compromise of the affected device remains significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.01b06CPE matchmatch criteria | cpe:2.3:o:dlink:dap-1860_firmware:1.01b06:*:*:*:*:*:*:* | ||
1.02b01CPE matchmatch criteria | cpe:2.3:o:dlink:dap-1860_firmware:1.02b01:*:*:*:*:*:*:* | ||
1.04b01CPE matchmatch criteria | cpe:2.3:o:dlink:dap-1860_firmware:1.04b01:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.