← Back to browse · API

CVE-2019-17621

Severity
CRITICAL
CVSS
9.8
EPSS
0.89624
Risk score
56.37
CISA KEV
Yes
PoC
No
Published
2019-12-30
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2019-7939, GHSA-4CJX-47HQ-7HC2
Products
D-Link:DIR-859 Router, n/a:n/a n/a
Sources
cisa.gov CVE-2019-17621
euvd EUVD-2019-7939

Description

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

References