CVE-2019-20500
D-Link DWL-2600AP Access Point Command Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
YesDecision
Descriptions
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.
Los dispositivos D-Link DWL-2600AP versión 4.2.0.15 Rev A, presentan una vulnerabilidad de inyección de comandos del Sistema Operativo autenticado por medio de la funcionalidad Save Configuration en la interfaz web, utilizando metacaracteres de shell en el parámetro configBackup o downloadServerip de admin.cgi?action=config_save.
D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-05 CVE Reserved
- 2020-03-05 CVE Published
- 2023-06-29 Exploited in Wild
- 2023-07-20 KEV Due Date
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-10-19 EPSS Updated
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/46841 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10113 | 2023-04-26 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dlink Search vendor "Dlink" | Dwl-2600ap Firmware Search vendor "Dlink" for product "Dwl-2600ap Firmware" | <= 4.2.0.15 Search vendor "Dlink" for product "Dwl-2600ap Firmware" and version " <= 4.2.0.15" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dwl-2600ap Search vendor "Dlink" for product "Dwl-2600ap" | - | - |
Safe
|