8.8
CVSSv3

CVE-2019-19597

Published: 05/12/2019 Updated: 24/08/2020
CVSS v2 Base Score: 8.3 | Impact Score: 10 | Exploitability Score: 6.5
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 739
Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dap-1860_firmware 1.01b06

dlink dap-1860_firmware 1.02b01

dlink dap-1860_firmware 1.04b01