CVE-2016-20017
dlink dsl-2750b firmware
Published 19 Oct 2022 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 8 Jan 2024, with a remediation deadline of 29 Jan 2024 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
References
- seclists.org/fulldisclosure/2016/Feb/53 · Exploit, Mailing List, Third Party Advisory
- supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10088 · Patch, Vendor Advisory
- www.exploit-db.com/exploits/44760 · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-20017 · US Government Resource