CVE-2019-20500
KEV PoC moderateAuthenticated OS Command Injection in D-Link DWL-2600AP Access Point Web Interface
CISA: D-Link DWL-2600AP Access Point Command Injection Vulnerability
D-Link DWL-2600AP access points running firmware 4.2.0.15 Rev A contain an authenticated OS command injection flaw (CWE-78) in the web interface's Save Configuration function (admin.cgi?action=config_save). An attacker with valid credentials submits shell metacharacters in the configBackup or downloadServerip parameters, causing arbitrary operating-system commands to execute on the device. Successful exploitation yields command execution on the access point itself, which can be used to pivot into the local network or to conscript the device into botnets, consistent with the recently reported Mirai campaign targeting multiple IoT device flaws. Any organization still running the affected DWL-2600AP hardware is exposed, especially where the management web interface is reachable from untrusted networks. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-29, confirming active in-the-wild exploitation, and it carries a very high EPSS (~97%) alongside a public proof-of-concept (Exploit-DB 46841).
What to do: Inventory all DWL-2600AP units, identify devices on the vulnerable firmware revision, and apply D-Link's latest available firmware per vendor instructions; because this product line is end-of-life, CISA's required action explicitly permits discontinuing use of the product if updates are unavailable. In the interim, restrict access to the web management interface (admin.cgi) to trusted management networks, remove any internet exposure, and ensure default or shared administrator credentials have been changed, since exploitation requires authentication.
| D-Link DWL-2600AP Access Point (firmware) | 4.2.0.15 Rev A (the revision named in the advisory; no broader affected version range is specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.
- Affected
- D-Link DWL-2600AP Access Point
- Required action
- Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dwl-2600ap firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news4 stories
IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits
Unit 42 tracks a Mirai botnet campaign exploiting over 20 IoT vulnerabilities in routers, cameras and DVRs to build DDoS botnets since March 2023.
Since March 2023, Unit 42 has tracked threat actors exploiting more than 20 IoT vulnerabilities to spread a Mirai botnet variant, first seen downloading payloads from zvub.us on March 14, 2023. Exploited flaws span CVE-2023-1389 (TP-Link Archer), CVE-2022-30525 (Zyxel), CVE-2022-31499 (Nortek) and many router, camera and DVR bugs. The variant decrypts configuration strings with an XOR key derived from 0xDEADBEEF and lacks built-in credential brute forcing, so spreading relies on manual operator exploitation. Two campaigns observed since October 2022 share infrastructure and near-identical samples.