CVE-2019-20215 is a critical unauthenticated remote command execution vulnerability affecting D-Link DIR-859 1.05 and 1.06B01 Beta01 devices. Attackers can exploit a flaw in the ssdpcgi() function by sending a specially crafted M-SEARCH request containing a malicious urn: value, allowing arbitrary OS command execution. With a CVSS score of 9.8 (Critical), this vulnerability poses a significant risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, exploit modules are publicly available in Metasploit and ExploitDB, indicating a high likelihood of exploitation. Despite the availability of exploit code, there is currently no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.05CPE matchmatch criteria | cpe:2.3:o:dlink:dir-859_firmware:1.05:*:*:*:*:*:*:* | ||
1.06b01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-859_firmware:1.06b01:beta01:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.