漏洞信息详情
D-Link DIR-859 操作系统命令注入漏洞
漏洞简介
D-Link DIR-859是中国台湾友讯(D-Link)公司的一款无线路由器。
D-Link DIR-859 1.05版本和1.06B01 Beta01版本中涉及UPnP请求的代码存在安全漏洞。远程攻击者可借助特制的HTTP SUBSCRIBE请求利用该漏洞以root权限执行系统命令。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10146
参考网址
来源:supportannouncement.us.dlink.com
链接:https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10146
来源:medium.com
链接:https://medium.com/@s1kr10s/d-link-dir-859-rce-unautenticated-cve-2019-17621-en-d94b47a15104
来源:www.dlink.com
链接:https://www.dlink.com/en/security-bulletin
来源:supportannouncement.us.dlink.com
链接:https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10147
来源:www.ftc.gov
链接:https://www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdf
来源:MISC
链接:https://medium.com/@s1kr10s/d-link-dir-859-rce-unautenticated-cve-2019-17621-es-fad716629ff9
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-17621
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156054/D-Link-DIR-859-Unauthenticated-Remote-Command-Execution.html
受影响实体
暂无
补丁
- D-Link DIR-859 操作系统命令注入漏洞的修复措施<!--2019-12-30-->
还没有评论,来说两句吧...