Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-16920 PoC — 多款D-Link产品操作系统命令注入漏洞

Source
Associated Vulnerability
Title:多款D-Link产品操作系统命令注入漏洞 (CVE-2019-16920)
Description:D-Link DIR-655C等都是中国台湾友讯(D-Link)公司的一款无线路由器。 多款D-Link产品中存在操作系统命令注入漏洞。攻击者可利用该漏洞注入命令,进而入侵系统。以下产品及版本受到影响:D-Link DIR-655C;DIR-866L;DIR-652;DHP-1565等。
Description
D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565 contain an unauthenticated remote code execution vulnerability. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these issues also affected; DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
File Snapshot

id: CVE-2019-16920 info: name: D-Link Routers - Remote Code Execution author: dwisiswant0 sev ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.