← Back to browse · API

CVE-2019-10891

Severity
CRITICAL
CVSS
9.8
EPSS
0.19442
Risk score
46.0
CISA KEV
No
PoC
No
Published
2019-09-06
Modified
2025-01-09
First seen
2026-08-07
Aliases
EUVD-2019-2613, GHSA-FRJJ-4MJW-3GMF
Products
n/a:n/a n/a
Sources
euvd EUVD-2019-2613

Description

An issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls system() without checking the parameter that can be controlled by user, and finally allows remote attackers to execute arbitrary shell commands with a special HTTP header.

References