← Back to CVE List
Vulnerability Intelligence Report
D-Link Multiple Routers Command Injection Vulnerability

CVE-2019-16920

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:100.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
dlink dir-655_firmware all
dlink dir-655 cx
dlink dir-866l_firmware all
dlink dir-866l ax
dlink dir-652_firmware all
dlink dir-652 ax
dlink dhp-1565_firmware all
dlink dhp-1565 ax
dlink dir-855l_firmware all
dlink dir-855l all
dlink dap-1533_firmware all
dlink dap-1533 all
dlink dir-862l_firmware all
dlink dir-862l all
dlink dir-615_firmware all
dlink dir-615 all
dlink dir-835_firmware all
dlink dir-835 all
dlink dir-825_firmware all
dlink dir-825 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.996%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-09-27T00:00:00
Published2019-09-27T11:34:12
Last Updated2025-10-21T23:45:29

LINK COPIED TO CLIPBOARD