Incorrect default permissions in D-Link DIR-842 vsftpd configuration

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-19893?

CVE-2026-19893 is a vulnerability classified as Incorrect Default Permissions and Incorrect Privilege Assignment, affecting DIR-842 (affected versions: 2.01.B04). This vulnerability is rated Low, with a CVSS score of 2.3. Current sources do not report this vulnerability as exploited.

Overview

Original source data

A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult.

Affected products and scope

  • Confirmed affected scope: D-Link DIR-842 firmware 2.01.B04, with vsftpd and /etc/vsftpd.conf identified in the record.
  • D-Link's advisory describes the DIR-842 hardware revisions covered by that advisory as legacy and unsupported.
  • No unaffected parallel branch or fixed release is supplied. Do not infer that every other firmware version is safe merely because the record names one affected version.

Technical details

The affected component is vsftpd, and the named file is /etc/vsftpd.conf. The record describes an unknown function whose manipulation results in incorrect default permissions. VulDB further describes installation-time permissions as allowing anyone to modify installed files, which supports an integrity risk but does not identify the exact permission bits, owner, or code path involved. The CNA metrics characterize the attack as remotely reachable, high complexity, requiring low privileges and no user interaction. The public material does not establish the attacker-controlled parameter, network endpoint, authentication flow, or whether the remote operation directly writes the configuration file. The exact implementation mechanism therefore remains unknown.

Exploitability

  • The record explicitly describes network-reachable exploitation.
  • The CNA metrics describe high attack complexity, low privileges required, and no user interaction.
  • VulDB states that no exploit is available, and the normalized record sets public_exploit to false.
  • No campaign, victim, or specific abuse case is identified in the reviewed evidence. This does not prove that exploitation has never occurred outside the available evidence.

Technical impact

The primary technical impact is integrity loss because permissions for a configuration component may be set incorrectly. Successful exploitation could allow unauthorized modification of configuration or files governed by those permissions. The supplied metrics do not identify confidentiality or availability impact, but public details do not describe the complete exploitation chain. CWE-266 is listed alongside CWE-276, yet the available evidence does not demonstrate a complete privilege-escalation path or full device compromise.

Business impact

The confirmed consequence is weakened integrity protection around the router's service configuration. If an attacker satisfies the incompletely documented conditions, incorrect default permissions could enable unauthorized changes to configuration or related files; the available evidence does not establish the exact change that would result. The record does not establish a data-disclosure, service-outage, or arbitrary-code-execution scenario. Operationally, devices in the legacy product family may need replacement because the vendor does not plan additional firmware development.

Remediation

  1. Replace the D-Link DIR-842 with a currently supported device. D-Link states that no additional firmware development is planned for the covered legacy hardware revisions.
  2. If immediate replacement is not possible, use the most recent firmware previously released for the exact hardware revision and region. This is vendor guidance, not a confirmed fixed release for this vulnerability.
  3. Disable remote management when it is not required. Use a strong, unique administrative password and enable Wi-Fi encryption with a non-reused password.
  4. Restrict the device from untrusted networks while replacement is pending, and monitor for unexpected changes to vsftpd configuration where the platform supports that review.
  5. Do not treat a different firmware branch as fixed or unaffected without vendor confirmation.

Detection

  1. Inventory D-Link DIR-842 devices, their hardware revisions, and installed firmware; compare them with the affected firmware branch listed in affected_summary.
  2. Where suitable access is available, inspect the device firmware or diagnostic interface for vsftpd and /etc/vsftpd.conf; record the actual owner and permission bits.
  3. Check whether remote management is enabled and verify that the device is not exposed beyond the required network boundary.
  4. If administrative or configuration-change logs exist, review them for unexpected changes involving vsftpd configuration. This is precautionary monitoring, not a confirmed indicator of compromise.
  5. No specific log signature, IOC, or expected permission baseline is provided. Absence of suspicious log entries does not prove that the device is safe.
Sources (20)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan