VDB
CVE-2019-16920
CVE-2019-16920
PUBLISHED
KEV
CVSS 10 CRITICAL
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
EPSS 94.34% · 100.0th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
94.34%
100.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| dlink | dir-615_firmware | |
| dlink | dir-655_firmware | 0 |
| n/a | n/a | n/a |
| dlink | dir-825_firmware | |
| dlink | dir-855l_firmware | |
| dlink | dir-862l_firmware | |
| dlink | dir-652_firmware | |
| dlink | dir-835_firmware | |
| dlink | dhp-1565_firmware | 0 |
| dlink | dap-1533_firmware | |
| dlink | dir-866l_firmware | 0 |
Timeline
- Sep 27, 2019 CVE Published
- Jun 10, 2020 PoC Published
- Oct 9, 2020 PoC Published
- Oct 15, 2020 PoC Published
- Oct 15, 2020 PoC Published
- Oct 16, 2020 PoC Published
- Oct 16, 2020 PoC Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
References
- https://www.seebug.org/vuldb/ssvid-98079 url
- https://fortiguard.com/zeroday/FG-VD-19-117 url
- https://medium.com/%4080vul/determine-the-device-model-affected-by-cve-2019-16920-by-zoomeye-bf6fec7f9bb3 url
- VU#766427 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16920 url
- https://nvd.nist.gov/vuln/detail/CVE-2019-16920 advisory