Executive brief
D-Link DSL-2750B devices contain a command injection vulnerability in the login.cgi component. Remote, unauthenticated attackers can execute arbitrary commands via the 'cli' parameter.
Affected products
- D-Link DSL-2750B firmware before 1.05
- D-Link DSL-2750B hardware
Timeline
- 2016-02-11: disclosed: Initial public disclosure on Full Disclosure mailing list
- 2022-10-19: other: NVD Published Date
- 2024-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2016-2022: exploited: Exploited in the wild during this period