890
VMScore

CVE-2019-17508

Published: 11/10/2019 Updated: 16/10/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dir-859 a3 firmware 1.06

dlink dir-850l a firmware 1.13