Vulnerability Details CVE-2019-9122
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.096
EPSS Ranking 92.5%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2019-9122
-
cpe:2.3:h:dlink:dir-825_rev.b:-
-
cpe:2.3:o:dlink:dir-825_rev.b_firmware:2.10