Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-7297

An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request. This occurs when the GetNetworkTomographyResult function calls the system function with an untrusted input parameter named Address. Consequently, an attacker can execute any command remotely when they control this input.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.213
EPSS Ranking 95.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2019-7297


Contact Us

Shodan ® - All rights reserved