CVE-2019-16057
KEV ransomware PoC largeUnauthenticated RCE via Command Injection in D-Link DNS-320 NAS
CISA: D-Link DNS-320 Remote Code Execution Vulnerability
CVE-2019-16057 is a remote command injection flaw (CWE-78) in the login_mgr.cgi script of D-Link DNS-320 NAS firmware through version 2.05.B10. An attacker can trigger it by sending a crafted, unauthenticated HTTP request to login_mgr.cgi, causing injected operating-system commands to execute on the device. Successful exploitation yields full remote code execution on the NAS, giving the attacker control over stored data and a network foothold that can enable lateral movement or ransomware staging. Any D-Link DNS-320 running vulnerable firmware is affected, with directly internet-exposed units at greatest risk. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-15) with known ransomware use, a public proof-of-concept is available, and EPSS puts the 30-day exploitation probability at 87.1%.
What to do: Per CISA's required action, the DNS-320 is end-of-life and should be disconnected from the network if still in use, prioritizing any unit reachable from the internet. Check D-Link's support site for any final firmware release before retiring the device, and audit retained units for signs of compromise (unexpected processes or outbound connections) given known ransomware use.
| D-Link DNS-320 Storage Device (ShareCenter NAS) firmware | through 2.05.B10 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
- Affected
- D-Link DNS-320 Storage Device
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Known
- Vendors
- dlink
- Products
- dns-320 firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.