CVE-2019-17621
KEV PoC ×2largeUnauthenticated Root Command Injection in D-Link DIR-859 Router UPnP
CISA: D-Link DIR-859 Router Command Execution Vulnerability
CVE-2019-17621 is an unauthenticated OS command injection flaw (CWE-78) in the UPnP endpoint /gena.cgi of D-Link DIR-859 Wi-Fi router firmware 1.05 and 1.06B01 Beta01. An attacker who can reach the UPnP service — typically by being on the local network — sends a specially crafted HTTP SUBSCRIBE request that injects and executes system commands. Because the service runs with root privileges, successful exploitation gives the attacker full control of the router, enabling configuration changes, traffic manipulation, and recruitment into botnets such as Mirai. The CISA-affected product is the DIR-859, with related D-Link DIR-series router firmware also listed in the CPE data, and public proof-of-concept references are available. The flaw is actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-29, and current headlines describe Mirai botnet campaigns leveraging it among multiple IoT flaws.
What to do: Apply the latest D-Link firmware updates per vendor instructions; because the DIR-859 is an older model that may no longer receive updates, CISA's required action is to discontinue use of the product if a fixed release is unavailable. If the router is not at end of life, restrict or disable UPnP where unused and ensure the UPnP endpoint is not reachable beyond the LAN, then check for signs of botnet compromise such as unusual outbound traffic or unauthorized configuration changes.
| D-Link DIR-859 Wi-Fi router firmware | 1.05 and 1.06B01 Beta01 (per CVE description; CISA-affected product) |
| D-Link DIR-822 firmware | — |
| D-Link DIR-823 firmware | — |
| D-Link DIR-865L firmware | — |
| D-Link DIR-868L firmware | — |
| D-Link DIR-869 firmware | — |
| D-Link DIR-880L firmware | — |
| D-Link DIR-890L firmware | — |
| D-Link DIR-890R firmware | — |
| D-Link DIR-885L firmware | — |
| D-Link DIR-885R firmware | — |
| D-Link DIR-895L firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
- Affected
- D-Link DIR-859 Router
- Required action
- Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dir-859 firmware, dir-822 firmware, dir-823 firmware, dir-865l firmware, dir-868l firmware, dir-869 firmware, dir-880l firmware, dir-890l firmware, dir-890r firmware, dir-885l firmware, dir-885r firmware, dir-895l firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news5 stories
IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits
Unit 42 tracks a Mirai botnet campaign exploiting over 20 IoT vulnerabilities in routers, cameras and DVRs to build DDoS botnets since March 2023.
Since March 2023, Unit 42 has tracked threat actors exploiting more than 20 IoT vulnerabilities to spread a Mirai botnet variant, first seen downloading payloads from zvub.us on March 14, 2023. Exploited flaws span CVE-2023-1389 (TP-Link Archer), CVE-2022-30525 (Zyxel), CVE-2022-31499 (Nortek) and many router, camera and DVR bugs. The variant decrypts configuration strings with an XOR key derived from 0xDEADBEEF and lacks built-in credential brute forcing, so spreading relies on manual operator exploitation. Two campaigns observed since October 2022 share infrastructure and near-identical samples.