ZeroHour

CVE-2019-16057

KEV ransomware PoC large

Unauthenticated RCE via Command Injection in D-Link DNS-320 NAS

CISA: D-Link DNS-320 Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
87%p100
Published
()
KEV added
AI analysis

CVE-2019-16057 is a remote command injection flaw (CWE-78) in the login_mgr.cgi script of D-Link DNS-320 NAS firmware through version 2.05.B10. An attacker can trigger it by sending a crafted, unauthenticated HTTP request to login_mgr.cgi, causing injected operating-system commands to execute on the device. Successful exploitation yields full remote code execution on the NAS, giving the attacker control over stored data and a network foothold that can enable lateral movement or ransomware staging. Any D-Link DNS-320 running vulnerable firmware is affected, with directly internet-exposed units at greatest risk. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-15) with known ransomware use, a public proof-of-concept is available, and EPSS puts the 30-day exploitation probability at 87.1%.

What to do: Per CISA's required action, the DNS-320 is end-of-life and should be disconnected from the network if still in use, prioritizing any unit reachable from the internet. Check D-Link's support site for any final firmware release before retiring the device, and audit retained units for signs of compromise (unexpected processes or outbound connections) given known ransomware use.

Affected
D-Link DNS-320 Storage Device (ShareCenter NAS) firmwarethrough 2.05.B10
Estimated exposure
largeorder of tens of thousands of internet-exposed DNS-320 devices (≈10,000–100,000 units; estimate) — The DNS-320 was a mass-market consumer and small-office NAS that reached end-of-life, and public internet scans have historically shown tens of thousands of legacy D-Link NAS devices exposed online, so the exposed-device count is estimated…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

CISA Known Exploited Vulnerability
Affected
D-Link DNS-320 Storage Device
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Known
Vendors
dlink
Products
dns-320 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.