← All CVEs

CVE-2019-16920

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

The impacted product is end-of-life and should be disconnected if still in use.

Added 2022-03-25Remediation due 2022-04-15

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

9.8
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2019-09-27
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
dlinkdir-655_firmware<= 3.02b05
dlinkdir-655cx
dlinkdir-866l_firmware<= 1.03b04
dlinkdir-866lax
dlinkdir-652_firmwareall versions
dlinkdir-652ax
dlinkdhp-1565_firmware<= 1.01
dlinkdhp-1565ax
dlinkdir-855l_firmwareall versions
dlinkdir-855lall versions
dlinkdap-1533_firmwareall versions
dlinkdap-1533all versions
dlinkdir-862l_firmwareall versions
dlinkdir-862lall versions
dlinkdir-615_firmwareall versions
dlinkdir-615all versions
dlinkdir-835_firmwareall versions
dlinkdir-835all versions
dlinkdir-825_firmwareall versions
dlinkdir-825all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-16920