cbcvebase.
CVE-2020-15893
published 2020-07-22

CVE-2020-15893: An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can…

PriorityP185critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
20.86%
97.3th percentile
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.

Affected

2 ranges
VendorProductVersion rangeFixed in
dlinkdir-816l_firmware
dlinkdir-816l_firmware

Detection & IOCsextracted from sources · hover to see the quote

port1900
commandM-SEARCH SSDP packet with malicious ST (Search Target) field
  • Monitor UDP port 1900 for SSDP M-SEARCH packets containing shell metacharacters or command injection payloads in the ST (Search Target) field.
  • Successful exploitation results in remote command execution with root privileges; look for unexpected root-level processes spawned from UPnP daemon on affected D-Link devices.
  • Watch for use of `wget` or `echo` commands as payload delivery mechanisms (cmdstager flavors) following exploitation of the UPnP M-SEARCH vector.
  • Stageless Meterpreter payloads are preferred by attackers over staged payloads for this exploit; detect Linux stageless Meterpreter beaconing from D-Link device IPs.
  • ·UPnP is enabled by default on affected D-Link devices, making them exposed without any additional attacker precondition. The attack is unauthenticated and requires only network access to UDP port 1900.
  • ·The vulnerability affects a very broad range of D-Link models and firmware versions beyond just DIR-816L, including DIR-300, DIR-600, DIR-645, DIR-815, DIR-817LW, DIR-818LW, DIR-822, DIR-823, DIR-845L, DIR-859, DIR-860L, DIR-865L, DIR-868L, DIR-869, DIR-880L, DIR-890L/R, DIR-885L/R, DIR-895L/R, and GO-RT-AC750.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.