CVE-2019-17621: D-Link DIR-859 Router Command Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-06-29. EPSS: 89.6% chance of exploitation in the next 30 days.

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

Affected products

  • D-Link Dir-818lx Firmware: affected versions not specified
  • D-Link Dir-822 Firmware: up to and including 2.03b01; up to and including 3.12b04
  • D-Link Dir-823 Firmware: up to and including 1.00b06; version 1.00b06 only
  • D-Link DIR-859 Firmware: up to and including 1.05b03; version 1.06b01 only
  • D-Link Dir-865l Firmware: up to and including 1.07b01
  • D-Link Dir-868l Firmware: up to and including 1.12b04; up to and including 2.05b02
  • D-Link Dir-869 Firmware: up to and including 1.03b02; version 1.03b02 only
  • D-Link Dir-880l Firmware: up to and including 1.08b04
  • D-Link Dir-885l Firmware: up to and including 1.12b05
  • D-Link Dir-885r Firmware: up to and including 1.12b05
  • D-Link Dir-890l Firmware: up to and including 1.11b01; version 1.11b01 only
  • D-Link Dir-890r Firmware: up to and including 1.11b01; version 1.11b01 only
  • D-Link Dir-895l Firmware: up to and including 1.12b10
  • D-Link Dir-895r Firmware: up to and including 1.12b10

Published 2019-12-30. Last modified 2026-06-17.