Critical severity9.8CISA KEVNVD Advisory· Published Dec 30, 2019· Updated Jun 17, 2026
CVE-2019-17621
CVE-2019-17621
Description
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21- cpe:2.3:o:dlink:dir-818lx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-823_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:dlink:dir-823_firmware:*:*:*:*:*:*:*:*range: <=1.00b06
- cpe:2.3:o:dlink:dir-823_firmware:1.00b06:beta:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-859_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:dlink:dir-859_firmware:*:*:*:*:*:*:*:*range: <=1.05b03
- cpe:2.3:o:dlink:dir-859_firmware:1.06b01:beta1:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-869_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:dlink:dir-869_firmware:*:*:*:*:*:*:*:*range: <=1.03b02
- cpe:2.3:o:dlink:dir-869_firmware:1.03b02:beta02:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-890l_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:dlink:dir-890l_firmware:*:*:*:*:*:*:*:*range: <=1.11b01
- cpe:2.3:o:dlink:dir-890l_firmware:1.11b01:beta01:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-890r_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:dlink:dir-890r_firmware:*:*:*:*:*:*:*:*range: <=1.11b01
- cpe:2.3:o:dlink:dir-890r_firmware:1.11b01:beta01:*:*:*:*:*:*
- D-Link/DIR-859 Wi-Fi routerdescription
Patches
Vulnerability mechanics
References
8- supportannouncement.us.dlink.com/announcement/publication.aspxnvdPatchVendor Advisory
- supportannouncement.us.dlink.com/announcement/publication.aspxnvdPatchVendor Advisory
- packetstormsecurity.com/files/156054/D-Link-DIR-859-Unauthenticated-Remote-Command-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- medium.com/%40s1kr10s/d-link-dir-859-rce-unautenticated-cve-2019-17621-en-d94b47a15104nvdExploitThird Party Advisory
- www.dlink.com/en/security-bulletinnvdVendor Advisory
- www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdfnvdThird Party AdvisoryUS Government Resource
- medium.com/%40s1kr10s/d-link-dir-859-rce-unautenticated-cve-2019-17621-es-fad716629ff9nvdBroken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.