VDB

CVE-2019-16920

CVE-2019-16920 PUBLISHED KEV CVSS 10 CRITICAL

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

EPSS 94.34% · 100.0th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
94.34%
100.0th percentile

Affected Products

VendorProductVersions
dlinkdir-615_firmware
dlinkdir-655_firmware0
n/an/an/a
dlinkdir-825_firmware
dlinkdir-855l_firmware
dlinkdir-862l_firmware
dlinkdir-652_firmware
dlinkdir-835_firmware
dlinkdhp-1565_firmware0
dlinkdap-1533_firmware
dlinkdir-866l_firmware0

Timeline

  • Sep 27, 2019 CVE Published
  • Jun 10, 2020 PoC Published
  • Oct 9, 2020 PoC Published
  • Oct 15, 2020 PoC Published
  • Oct 15, 2020 PoC Published
  • Oct 16, 2020 PoC Published
  • Oct 16, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›