← לוח פגיעויות

CVE-2019-20500

גבוהה 7.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
D-Link DWL-2600AP Access Point Command Injection Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

תיאור (מקור, אנגלית)

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.

מדדים

CVSS 3.1
7.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
97% (אחוזון 100) נכון ל-4/8/2026
CWE
CWE-78

מוצרים מושפעים

dlink: dwl-2600ap firmware; dlink: dwl-2600ap

קישורים