Vulnerability record · CVE-2019-17621 · published 30 December 2019
CVE-2019-17621: D-Link DIR-859 UPnP gena.cgi unauthenticated command injection
Dlink · Dir 859 Firmware
The UPnP endpoint /gena.cgi on D-Link DIR-859 firmware 1.05 and 1.06B01 Beta01 fails to sanitize input in an HTTP SUBSCRIBE request, allowing OS command injection. An attacker on the local network can run arbitrary system commands as root without authenticating, giving full control of the router.
Description
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote root command execution with a CVSS of 9.8, KEV listing, and near-maximum EPSS makes this an urgent patch-or-replace item.
What it is
The UPnP endpoint /gena.cgi on D-Link DIR-859 firmware 1.05 and 1.06B01 Beta01 fails to sanitize input in an HTTP SUBSCRIBE request, allowing OS command injection. An attacker on the local network can run arbitrary system commands as root without authenticating, giving full control of the router.
Impact
An attacker gains root-level command execution on the device, enabling full router compromise, traffic interception or redirection, and use of the device as a foothold into the connected network.
Attack surface
Reached over the network via a crafted HTTP SUBSCRIBE request to the UPnP service on /gena.cgi; no authentication or user interaction is required, but the description states the attacker must be connecting to the local network.
Exploitation
CISA added this to KEV on 2023-06-29 with a 2023-07-20 remediation due date, and EPSS is 0.89624 (99.8th percentile); public exploit references are tagged Exploit, though no ransomware use is documented.
What to do
- Apply the D-Link vendor updates referenced in advisories SAP10146 and SAP10147, or discontinue use of the affected product if no update is available.
- Disable UPnP on the router if it is not operationally required.
- Restrict router management and UPnP exposure to trusted internal segments only; do not expose the device to untrusted networks.
- Replace end-of-support D-Link models with vendor-supported hardware.
- Inventory the listed DIR-series models and confirm firmware versions against vendor advisories.
Detection
- Monitor router and perimeter logs for HTTP SUBSCRIBE requests to /gena.cgi, especially with unusual or shell-like characters in headers.
- Alert on unexpected outbound connections or processes originating from the router.
- Watch for anomalous UPnP traffic on the local network from non-media or non-IoT hosts.
- Check for unauthorized configuration changes or new admin accounts on affected routers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-17621 to the Known Exploited Vulnerabilities catalog on 29 June 2023 as "D-Link DIR-859 Router Command Execution Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 20 July 2023.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-17621 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-17621), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.