CVE-2019-20213: D-Link Dir-818lx Firmware
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
Affected products
- D-Link Dir-818lx Firmware: affected versions not specified
- D-Link Dir-822 Firmware: up to and including 2.03b01; up to and including 3.12b04
- D-Link Dir-823 Firmware: up to and including 1.00b06
- D-Link DIR-859 Firmware: up to and including 1.05b03; version 1.06b01 only
- D-Link Dir-865l Firmware: up to and including 1.07b01
- D-Link Dir-868l Firmware: up to and including 1.12b04; up to and including 2.05b02
- D-Link Dir-869 Firmware: up to and including 1.03b02
- D-Link Dir-880l Firmware: up to and including 1.08b04
- D-Link Dir-885l Firmware: up to and including 1.12b05
- D-Link Dir-885r Firmware: up to and including 1.12b05
- D-Link Dir-890l Firmware: up to and including 1.11b01
- D-Link Dir-890r Firmware: up to and including 1.11b01
- D-Link Dir-895l Firmware: up to and including 1.12b10
- D-Link Dir-895r Firmware: up to and including 1.12b10
Published 2020-01-02. Last modified 2026-06-17.