Dir 859
Vendor:
First CVE: Dec 30, 2019 · Active for 6 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
9.0
Avg CVSS
Higher Avg CVSS than 83% of tracked products
25.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Dir 859 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2019
6 years ago
Most Recent CVE
Jan 21, 2024
916 days ago
CVE Severity & Scoring
Dir 8598 CVEs
13%
13%
75%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17621CRITICAL The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending | Dec 30, 2019 | 9.8 | 97 | YES | YES |
CVE-2024-0769CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file | Jan 21, 2024 | 9.8 | 95 | YES | NO |
CVE-2019-20215CRITICAL D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTT | Jan 29, 2020 | 9.8 | 86 | NO | YES |
CVE-2019-20216CRITICAL D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because R | Jan 29, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-20217CRITICAL D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because S | Jan 29, 2020 | 9.8 | 30 | NO | NO |
CVE-2023-36092CRITICAL Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects produ | Jul 31, 2023 | 9.8 | 27 | NO | NO |
CVE-2019-20213HIGH D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php. | Jan 2, 2020 | 7.5 | 25 | NO | NO |
CVE-2022-25106MEDIUM D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to cause a Denial of Service (DoS) v | Mar 4, 2022 | 5.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
2 CVEs
25.0% of CVEs· 98th percentile
Metasploit
2 CVEs
25.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Dir 859
Top CWEs
Versions
No cataloged versions.