ZeroHour

CVE-2019-16920

KEV PoC ×2mass

Command Injection in Multiple D-Link Routers Enables Full Device Compromise

CISA: D-Link Multiple Routers Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Multiple D-Link routers contain a command injection flaw (CWE-78) in which attacker-controlled input is executed as operating system commands by the device. An attacker who triggers the flaw can run arbitrary commands on the router with system privileges, achieving full compromise of the device, from which they can intercept or redirect traffic, pivot to the local network, or persist on the device. The specific affected models and firmware version ranges are not enumerated in the available data, but CISA notes the impacted product line is end-of-life, so only devices still in service are at risk. This vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-25, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is known, but the KEV listing means defenders should treat exploitation as active, not theoretical.

What to do: Inventory your environment for D-Link routers and identify any running the affected end-of-life models; per CISA's required action, disconnect or retire them if still in use since they no longer receive fixes. If a device must remain in service, restrict management access (disable WAN-side web administration, limit it to trusted management networks) and monitor for compromise indicators. Confirm whether any internet-facing D-Link routers are exposed and prioritize replacement of EOL units.

Affected
D-Link
Estimated exposure
massplausibly hundreds of thousands of internet-exposed D-Link routers and millions sold overall; exact count of in-use affected units unknown — D-Link is one of the largest consumer/SOHO router vendors, and public internet-wide scans routinely show hundreds of thousands of exposed D-Link devices, though the share running the affected end-of-life models is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

CISA Known Exploited Vulnerability
Affected
D-Link Multiple Routers
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dir-655 firmware, dir-866l firmware, dir-652 firmware, dhp-1565 firmware, dir-855l firmware, dap-1533 firmware, dir-862l firmware, dir-615 firmware, dir-835 firmware, dir-825 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news