Back

CVE-2019-7297

CRITICAL

An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request. This occurs when the GetNetworkTomographyResult function calls the system function with an untrusted input parameter named Address. Consequently, an attacker can execute any command remotely when they control this input.

Published: Jan 31, 2019 Modified: Jun 17, 2026
CWE-78

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
d-link dir-823g_firmware *

GitHub Security Advisory GHSA-8jwc-8ww6-25xw

An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 12.46%

Top 4% most likely to be exploited

Threat Score 42.9 / 100

Data Sources

NVD EPSS GitHub