CVE-2019-17508
23Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 16%
from disclosure to weapon0 days
Published on NVDOct 11
metasploitAug 9
exploitation probability
16%top 3% of all CVEs
observed exploitation
nono source reports it
On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.
Affected products
n/a · n/a