peter bassill · operator
$ cve CVE-2019-16920 JSON

CVE-2019-16920 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2022-04-15
Public exploitnone known
Published2019-09-27
Last modified2026-06-17

CISA KEV

NameD-Link Multiple Routers Command Injection Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productD-Link / Multiple Routers
Ransomware usenone reported

Affected (20)

VendorProduct
dlinkdap-1533
dlinkdap-1533 firmware
dlinkdhp-1565
dlinkdhp-1565 firmware
dlinkdir-615
dlinkdir-615 firmware
dlinkdir-652
dlinkdir-652 firmware
dlinkdir-655
dlinkdir-655 firmware
dlinkdir-825
dlinkdir-825 firmware
dlinkdir-835
dlinkdir-835 firmware
dlinkdir-855l
dlinkdir-855l firmware
dlinkdir-862l
dlinkdir-862l firmware
dlinkdir-866l
dlinkdir-866l firmware

References

→ the Explorer  ·  watch your stack  ·  NVD