CVE-2019-16920
dlink dir-655 firmware, dlink dir-866l firmware, dlink dir-652 firmware
Published 27 Sept 2019 · updated 17 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 25 Mar 2022, with a remediation deadline of 15 Apr 2022 for US federal agencies.
Required action: The impacted product is end-of-life and should be disconnected if still in use.
Description
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
References
- fortiguard.com/zeroday/FG-VD-19-117 · Broken Link, Third Party Advisory
- medium.com/%4080vul/determine-the-device-model-affected-by-cve-2019-16920-by-zoomeye-bf6fec7f9bb3 · Exploit, Third Party Advisory
- www.kb.cert.org/vuls/id/766427 · Third Party Advisory, US Government Resource
- www.seebug.org/vuldb/ssvid-98079 · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16920 · US Government Resource