Vulnerabilities
Vulnerable Software
Dlink:  >> Dir-866l  Security Vulnerabilities
D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-10-16
CVE-2019-16920
Known exploited
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
CVSS Score
9.8
EPSS Score
0.943
Published
2019-09-27


Contact Us

Shodan ® - All rights reserved