Executive brief
The D-Link DIR-859 router contains an OS command injection vulnerability in the UPnP endpoint /gena.cgi. An unauthenticated remote attacker can execute arbitrary commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service.
Affected products
- D-Link DIR-859 1.05, 1.06B01 Beta01
Timeline
- 2023-06-29: disclosed
- 2023-06-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-06-29: advisory: NVD publication date
- 2023-06-29: exploited: Confirmed exploited in the wild per CISA KEV entry.