ZeroHour

CVE-2016-20017

KEV PoC ×2large

Unauthenticated Command Injection in D-Link DSL-2750B Router login.cgi

CISA: D-Link DSL-2750B Devices Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
65%p99
Published
()
KEV added
AI analysis

D-Link DSL-2750B routers running firmware before 1.05 contain an unauthenticated command injection flaw (CWE-77) in the 'cli' parameter of the login.cgi web endpoint. An attacker can trigger it remotely by sending a crafted HTTP request to login.cgi with shell metacharacters embedded in the cli parameter, requiring no credentials or user interaction. Successful exploitation yields arbitrary command execution on the router, giving the attacker full control of the device, which can be used for traffic interception, persistence, or recruitment into botnets such as the Mirai-based IZ1H9 campaign noted in recent reporting. Any internet-facing DSL-2750B running affected firmware is exposed, and CISA added the issue to the Known Exploited Vulnerabilities catalog on 2024-01-08 after exploitation observed in the wild from 2016 through 2022. With a CVSS of 9.8 and an EPSS of ~65%, exploitation pressure on unpatched devices remains high.

What to do: Upgrade DSL-2750B firmware to version 1.05 or later per vendor instructions; if an update is unavailable or the device is end-of-life, follow CISA's required action and discontinue use or restrict web (HTTP) management access to trusted networks only. Defenders should check device logs for suspicious unauthenticated requests to login.cgi containing shell metacharacters in the cli parameter, as these indicate exploitation attempts.

Affected
D-Link DSL-2750B firmwarebefore 1.05
Estimated exposure
largetens of thousands to ~100,000 internet-exposed DSL-2750B routers — The DSL-2750B was an ISP-distributed consumer DSL gateway deployed in large volumes, and internet-wide router scans plus sustained botnet exploitation from 2016-2022 indicate a substantial exposed population, though no exact scan count is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.

CISA Known Exploited Vulnerability
Affected
D-Link DSL-2750B Devices
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dsl-2750b firmware
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news