Evidence dossier

CVE-2019-17621

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by…

Exploited in the wild (CISA KEV since Jun 29, 2023). NVD reports CVSS 3.1 9.8. EPSS estimates 89.6% exploit likelihood as of Aug 26, 2026.

90.491.2Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

State
PUBLISHED
Published
Dec 30, 2019
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    mitre

    Record text: The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

    Inspect raw assertion
    Field
    container
    Value
    The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: D-Link DIR-859 Router Command Execution Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    D-Link DIR-859 Router Command Execution Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 89.62% probability · 99.78th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.896240000000; percentile 0.997750000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Jun 29, 2023 · first observed Jul 19, 2026

Exploit likelihood89.62%

FIRST EPSS · score date Aug 26, 2026 · 99.8th percentile · first observed Aug 26, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
mitreOriginal assertion
Record text

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

Inspect raw assertion
Field
container
Value
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

D-Link DIR-859 Router Command Execution Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
D-Link DIR-859 Router Command Execution Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

89.62% probability · 99.78th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.896240000000; percentile 0.997750000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
37Underlying assertions
28Canonical products
21Target assertions
16Constraint assertions

Grouped from 32 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

29 scope groups

mitre · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · HARDWAREdlinkdir-818lxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-a5ee1f477db2f4d42d1e40c729ae5c70d37223566853e61f8da2c2072175e0bbLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dir-818lx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    15 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1b6e718c-2e2a-4e9b-a83d-25c01f681301
NVD CPE · OPERATING SYSTEMdlinkdir-818lx_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-6c79586e1f13779993fd6de428c4a1ff75d870710d8f6ee36b40c19ea02b3738Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dir-818lx_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    15 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    072f053e-4dab-4246-bee7-f4813957bf56
NVD CPE · HARDWAREdlinkdir-822Environmental constraint · 2 assertions
Version not applicableCanonical identity product-926d9c9249b8e91d7dc22920727941e7b2277eb29de21c912a78c73728c11811Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:dlink:dir-822:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b3894f0e-37f8-4a89-87ac-1db524d4ae04
  2. cpe:2.3:h:dlink:dir-822:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b3894f0e-37f8-4a89-87ac-1db524d4ae04
NVD CPE · OPERATING SYSTEMdlinkdir-822_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (<= 2.03b01); Any version (unconstrained) (<= 3.12b04)Canonical identity product-97981aa0623e8052f1216534d087b32e8ad38fdf35ef81c8677756774c9d2803Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:dlink:dir-822_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 3.12b04
    Match ID
    46b25758-8ec2-4598-a834-9d513b030629
  2. cpe:2.3:o:dlink:dir-822_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 2.03b01
    Match ID
    8f8e6cda-679a-4a31-8d8d-bd283c5e1e3e
NVD CPE · HARDWAREdlinkdir-823Environmental constraint · 1 assertions
Version not applicableCanonical identity product-abf14ee9101ecc66224f3295891ddf5655e095ea14686557dae4c9544b002c65Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dir-823:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ec426833-bea7-4029-bbbb-94688ee801bc
NVD CPE · OPERATING SYSTEMdlinkdir-823_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (<= 1.00b06); Version 1.00b06Canonical identity product-01c2ce233736165013fd05c3e10bb84f92a62e4467a240dc2ab423b67ac757a0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:dlink:dir-823_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.00b06
    Match ID
    99d9046b-206e-4267-98ba-bf572682f134
  2. cpe:2.3:o:dlink:dir-823_firmware:1.00b06:beta:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5a56d2bd-5160-46fe-8ac7-cb4ca50e4d5d
NVD CPE · HARDWAREdlinkdir-859Environmental constraint · 1 assertions
Version not applicableCanonical identity product-d85c535ec360b5468f3c0d1668f6172c54f574dedf8e5128c73ec905a0aae3bfLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dir-859:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1deef5b-d8e9-45f3-8a89-52ce8402e6f5
NVD CPE · OPERATING SYSTEMdlinkdir-859_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (<= 1.05b03); Version 1.06b01Canonical identity product-a8ac0778da4d9cd658c582bb971ea7f57de17e5d0a2c4886bff2fa0912212926Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:dlink:dir-859_firmware:1.06b01:beta1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb555a1a-6b26-483e-abfc-b64b928e7cc5
  2. cpe:2.3:o:dlink:dir-859_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.05b03
    Match ID
    c2abcf49-625f-4267-8b6d-14081b31e8b0
NVD CPE · HARDWAREdlinkdir-865lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-4b0699c4ec53d947d0a5516955a130b9b206afc791d464f7006fdd723c739f14Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dir-865l:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f3a853df-6df1-4e8e-8d55-95279ee0cb30
NVD CPE · OPERATING SYSTEMdlinkdir-865l_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 1.07b01)Canonical identity product-e7da0764731c1f6689a23a4335fa2fd9eb623fd70e2a26a8fd88c43879c09d08Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dir-865l_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.07b01
    Match ID
    4406996e-761d-4edc-9877-17b7472c1422
NVD CPE · HARDWAREdlinkdir-868lEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-21cf473255f901d239eab8f7b552335e4068c4b492766288b55b8d70a8a9b113Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:dlink:dir-868l:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    33b501d4-bddd-485e-a5a3-8aa8d5e46061
  2. cpe:2.3:h:dlink:dir-868l:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    33b501d4-bddd-485e-a5a3-8aa8d5e46061
NVD CPE · OPERATING SYSTEMdlinkdir-868l_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (<= 1.12b04); Any version (unconstrained) (<= 2.05b02)Canonical identity product-0882ef5a8c5a96f1ab04d223773550d81fb1c3ed7f4893baf99449a19fc8e7c3Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:dlink:dir-868l_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.12b04
    Match ID
    f9d90548-24fd-416f-9159-6f7ab318c923
  2. cpe:2.3:o:dlink:dir-868l_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 2.05b02
    Match ID
    0b0ca3a5-cf3d-4d1b-bb07-ee0d91901bc9
NVD CPE · HARDWAREdlinkdir-869Environmental constraint · 1 assertions
Version not applicableCanonical identity product-48218b69bea7ad19d37c5adb193a98d812c927b014bbbedca2945516b4e086c8Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dir-869:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e9eb6e8e-03fa-4477-b97a-0752b7c443f0
NVD CPE · OPERATING SYSTEMdlinkdir-869_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (<= 1.03b02); Version 1.03b02Canonical identity product-054086d979cc3abfcc2c2afb6904113f0d1dae8452567b6184f3fbd107781bf0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:dlink:dir-869_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.03b02
    Match ID
    499e8ada-b4ed-42b2-b237-716a77bd546a
  2. cpe:2.3:o:dlink:dir-869_firmware:1.03b02:beta02:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    af693676-c580-44cf-aac6-6e38658feafb
NVD CPE · HARDWAREdlinkdir-880lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-435f31c28177da8d3b298791a50734af5b1326cf9922e0b73c09626dc2a50aa2Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dir-880l:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cc772491-6371-4712-b358-e74d9c5062fd
NVD CPE · OPERATING SYSTEMdlinkdir-880l_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 1.08b04)Canonical identity product-d55ee25a5b5e6e3649424da41d1341ccc282f1957f019b66b05a4459890f0affLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dir-880l_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.08b04
    Match ID
    ae7c571b-bccb-4853-a08e-2ef9a64c94cd
NVD CPE · HARDWAREdlinkdir-885lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-7567cb4deb10431dcc9a0c27c4a2f859d93c9c7047e9f8147267dcc10dcdb92cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dir-885l:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad481b64-a25d-4123-b575-20ec3c524d9c
NVD CPE · OPERATING SYSTEMdlinkdir-885l_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 1.12b05)Canonical identity product-47a10c3fc5975dceaa5be40f8b36697f5a198e6855294688138ae876868d4b85Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dir-885l_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.12b05
    Match ID
    48d9c475-fb79-4d18-823c-0a3f01cb478e
NVD CPE · HARDWAREdlinkdir-885rEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-c26359b506c19c969ed4a65a843f515b108e1f548a4576d8da52cbc783a449d2Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dir-885r:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    12 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8e0351a1-d161-468e-a2c4-1fb92e978da7
NVD CPE · OPERATING SYSTEMdlinkdir-885r_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 1.12b05)Canonical identity product-4b72aac60d3b64f0e8fa19623d983db8a2764153efdc49044beea021ee947064Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dir-885r_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.12b05
    Match ID
    0261fba8-d370-4581-b4ae-e8dbf4546c50
NVD CPE · HARDWAREdlinkdir-890lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-7921e0b6726716afebcf5e0c77c02cbf0bcfa4900e143a45738587ce668cbc9fLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dir-890l:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b1ea89c7-4655-43a3-9d2b-d57640d56c09
NVD CPE · OPERATING SYSTEMdlinkdir-890l_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (<= 1.11b01); Version 1.11b01Canonical identity product-6be65671681b148d51228bd240c7e6c104ec48e506bca38485eae5ba81962d0dLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:dlink:dir-890l_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.11b01
    Match ID
    50fcdbdc-32f8-42df-bd3c-a9efc11d036c
  2. cpe:2.3:o:dlink:dir-890l_firmware:1.11b01:beta01:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7a4a1a68-5b14-47b7-9d02-274a0e4af2f2
NVD CPE · HARDWAREdlinkdir-890rEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-b59e388cb50051d5bdb1c585b04002ad079da434174da309a6d39942248f46c4Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dir-890r:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d678e889-3d74-4d16-84d0-41f547519a7f
NVD CPE · OPERATING SYSTEMdlinkdir-890r_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (<= 1.11b01); Version 1.11b01Canonical identity product-91ee048cffa06bf8a4629fd4609fccc8ada5df6e3307c30886d89dd3613fc24cLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:dlink:dir-890r_firmware:1.11b01:beta01:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4c18c9d9-9418-441b-9367-91f86137245c
  2. cpe:2.3:o:dlink:dir-890r_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.11b01
    Match ID
    da0beaad-6330-47fe-a8f6-665c3f346619

Affected-product evidence

Accepted scope and product mapping

14 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-01c2ce233736165013fd05c3e10bb84f92a62e4467a240dc2ab423b67ac757a0

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
48c25a07-213b-48fa-bfab-9d662856ee1cf579397c-0433-4919-9442-55e29757e38d
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-054086d979cc3abfcc2c2afb6904113f0d1dae8452567b6184f3fbd107781bf0

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
dc9d4575-abea-4eb2-ba1a-933278545e44f5a649ee-0006-4f38-8886-6e13b050c228
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-0882ef5a8c5a96f1ab04d223773550d81fb1c3ed7f4893baf99449a19fc8e7c3

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
cb39d19f-8f7a-4cdc-b7fb-0542fa78634bfc052824-f527-43bc-a41f-202673eee4e6
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-1740df7c61986c9e91e4f857461dbb7240bb0982598008328d48d66d76b12eae

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
347dda28-a947-4a14-a7be-4380871d6e42
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-47a10c3fc5975dceaa5be40f8b36697f5a198e6855294688138ae876868d4b85

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
205aa2b1-73d2-4cab-beb2-47fefd7c893d
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-4b72aac60d3b64f0e8fa19623d983db8a2764153efdc49044beea021ee947064

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c6c15817-c067-400c-ba3f-4030f5e288b2
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-6be65671681b148d51228bd240c7e6c104ec48e506bca38485eae5ba81962d0d

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8d8ba6c1-9592-480b-8e89-572ea84891999001d02d-320d-40c1-afc7-ee3a06c2d48c
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-6c79586e1f13779993fd6de428c4a1ff75d870710d8f6ee36b40c19ea02b3738

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
827f23c0-af4c-469f-9ca2-313e98b889c9
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-91ee048cffa06bf8a4629fd4609fccc8ada5df6e3307c30886d89dd3613fc24c

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
75bc4421-63ae-4aa4-beec-0813fbec396ce50d82cf-7899-48c1-8429-b8ad041daf06
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-97981aa0623e8052f1216534d087b32e8ad38fdf35ef81c8677756774c9d2803

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1fa2ced9-ba7a-46c4-8470-940dfd6eba009d6ea21f-102e-42a8-a14e-f79e1e83dfb8
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-a8ac0778da4d9cd658c582bb971ea7f57de17e5d0a2c4886bff2fa0912212926

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
932387e7-85cc-410f-ae67-eeb54e8c7125a51b1716-9005-4803-b106-2ab03ae9f992
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-d55ee25a5b5e6e3649424da41d1341ccc282f1957f019b66b05a4459890f0aff

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8e79bfe0-6b55-439f-89ce-c529e8163bb1
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-e7da0764731c1f6689a23a4335fa2fd9eb623fd70e2a26a8fd88c43879c09d08

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f270612d-d674-4b54-94b3-aeb9ad2609f6
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-fddafd02d22987e2bf332a954f8aafcdbf42eef9e7484a3be046c943d1563aef

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b696a0b0-f20e-4f92-bd7b-9668b4c8ba97
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3a0408bf-fada-4092-8ef4-9d58522db9bd

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:C/I:C/A:C
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.