CVE-2019-20213

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
02/01/2020
Last modified:
07/11/2023

Description

D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dir-859_firmware:*:*:*:*:*:*:*:* 1.05b03 (including)
cpe:2.3:o:dlink:dir-859_firmware:1.06b01:beta1:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-859:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-822_firmware:*:*:*:*:*:*:*:* 2.03b01 (including)
cpe:2.3:h:dlink:dir-822:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-822_firmware:*:*:*:*:*:*:*:* 3.12b04 (including)
cpe:2.3:h:dlink:dir-822:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-823_firmware:*:*:*:*:*:*:*:* 1.00b06 (including)
cpe:2.3:h:dlink:dir-823:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-865l_firmware:*:*:*:*:*:*:*:* 1.07b01 (including)
cpe:2.3:h:dlink:dir-865l:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-868l_firmware:*:*:*:*:*:*:*:* 1.12b04 (including)
cpe:2.3:h:dlink:dir-868l:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-868l_firmware:*:*:*:*:*:*:*:* 2.05b02 (including)
cpe:2.3:h:dlink:dir-868l:-:*:*:*:*:*:*:*