CVE-2019-16920
KEV PoC ×2massCommand Injection in Multiple D-Link Routers Enables Full Device Compromise
CISA: D-Link Multiple Routers Command Injection Vulnerability
Multiple D-Link routers contain a command injection flaw (CWE-78) in which attacker-controlled input is executed as operating system commands by the device. An attacker who triggers the flaw can run arbitrary commands on the router with system privileges, achieving full compromise of the device, from which they can intercept or redirect traffic, pivot to the local network, or persist on the device. The specific affected models and firmware version ranges are not enumerated in the available data, but CISA notes the impacted product line is end-of-life, so only devices still in service are at risk. This vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-25, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is known, but the KEV listing means defenders should treat exploitation as active, not theoretical.
What to do: Inventory your environment for D-Link routers and identify any running the affected end-of-life models; per CISA's required action, disconnect or retire them if still in use since they no longer receive fixes. If a device must remain in service, restrict management access (disable WAN-side web administration, limit it to trusted management networks) and monitor for compromise indicators. Confirm whether any internet-facing D-Link routers are exposed and prioritize replacement of EOL units.
| D-Link | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
- Affected
- D-Link Multiple Routers
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dir-655 firmware, dir-866l firmware, dir-652 firmware, dhp-1565 firmware, dir-855l firmware, dap-1533 firmware, dir-862l firmware, dir-615 firmware, dir-835 firmware, dir-825 firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H