CVE-2019-17506: D-Link Dir-817lw a1 Firmware

Critical severity, CVSS 9.8. EPSS: 56.4% chance of exploitation in the next 30 days.

There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.

Affected products

  • D-Link Dir-817lw a1 Firmware: version 1.04 only
  • D-Link Dir-868l b1 Firmware: version 2.03 only

Published 2019-10-11. Last modified 2026-06-17.