CVE-2019-16920 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-15.
Description
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 100% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2022-04-15 |
| Public exploit | none known |
| Published | 2019-09-27 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | D-Link Multiple Routers Command Injection Vulnerability |
|---|---|
| Added | 2022-03-25 |
| Due | 2022-04-15 |
| Vendor / product | D-Link / Multiple Routers |
| Ransomware use | none reported |
Affected (20)
| Vendor | Product |
|---|---|
| dlink | dap-1533 |
| dlink | dap-1533 firmware |
| dlink | dhp-1565 |
| dlink | dhp-1565 firmware |
| dlink | dir-615 |
| dlink | dir-615 firmware |
| dlink | dir-652 |
| dlink | dir-652 firmware |
| dlink | dir-655 |
| dlink | dir-655 firmware |
| dlink | dir-825 |
| dlink | dir-825 firmware |
| dlink | dir-835 |
| dlink | dir-835 firmware |
| dlink | dir-855l |
| dlink | dir-855l firmware |
| dlink | dir-862l |
| dlink | dir-862l firmware |
| dlink | dir-866l |
| dlink | dir-866l firmware |
References
- https://fortiguard.com/zeroday/FG-VD-19-117
- https://medium.com/%4080vul/determine-the-device-model-affected-by-cve-2019-16920-by-zoomeye-bf6fec7f9bb3
- https://www.kb.cert.org/vuls/id/766427
- https://www.seebug.org/vuldb/ssvid-98079
- https://fortiguard.com/zeroday/FG-VD-19-117
- https://medium.com/%4080vul/determine-the-device-model-affected-by-cve-2019-16920-by-zoomeye-bf6fec7f9bb3
- https://www.kb.cert.org/vuls/id/766427
- https://www.seebug.org/vuldb/ssvid-98079
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16920
→ the Explorer · watch your stack · NVD