CVE-2020-15893
published 2020-07-22CVE-2020-15893: An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can…
PriorityP185critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
20.86%
97.3th percentile
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-816l_firmware | — | — |
| dlink | dir-816l_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor UDP port 1900 for SSDP M-SEARCH packets containing shell metacharacters or command injection payloads in the ST (Search Target) field. ↗
- →Successful exploitation results in remote command execution with root privileges; look for unexpected root-level processes spawned from UPnP daemon on affected D-Link devices. ↗
- →Watch for use of `wget` or `echo` commands as payload delivery mechanisms (cmdstager flavors) following exploitation of the UPnP M-SEARCH vector. ↗
- →Stageless Meterpreter payloads are preferred by attackers over staged payloads for this exploit; detect Linux stageless Meterpreter beaconing from D-Link device IPs. ↗
- ·UPnP is enabled by default on affected D-Link devices, making them exposed without any additional attacker precondition. The attack is unauthenticated and requires only network access to UDP port 1900. ↗
- ·The vulnerability affects a very broad range of D-Link models and firmware versions beyond just DIR-816L, including DIR-300, DIR-600, DIR-645, DIR-815, DIR-817LW, DIR-818LW, DIR-822, DIR-823, DIR-845L, DIR-859, DIR-860L, DIR-865L, DIR-868L, DIR-869, DIR-880L, DIR-890L/R, DIR-885L/R, DIR-895L/R, and GO-RT-AC750. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q86m-xf2x-qj8j: An issue was discovered on D-Link DIR-816L devices 2
ghsa_unreviewed·2022-05-24
CVE-2020-15893 [HIGH] CWE-78 GHSA-q86m-xf2x-qj8j: An issue was discovered on D-Link DIR-816L devices 2
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.
VulnCheck
D-Link dir-816l_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2020·CVSS 9.8
CVE-2020-15893 [CRITICAL] D-Link dir-816l_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
D-Link dir-816l_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.
Affected: D-Link dir-816l_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.bleepingcomputer.com/news/security/reverse-shell-botnet-gitpaste-12-spreads-via-github-and-pastebin/#google_vignette
No detection rules found.
No writeups or analysis indexed.
https://research.loginsoft.com/bugs/multiple-vulnerabilities-discovered-in-the-d-link-firmware-dir-816l/https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10169https://research.loginsoft.com/bugs/multiple-vulnerabilities-discovered-in-the-d-link-firmware-dir-816l/https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10169
2020-07-22
Published
Exploited in the wild