Vulnerabilities > CVE-2019-9122 - Unspecified vulnerability in Dlink Dir-825 Rev.B Firmware 2.10

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
dlink

Summary

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.

Vulnerable Configurations

Part Description Count
OS
Dlink
1
Hardware
Dlink
1