Junglewise Threat Intelligence

CVE-2016-20017: D-Link DSL-2750B Devices Command Injection Vulnerability

CVE-2016-20017 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-01-08

Vendors: D-Link.

Executive brief

D-Link DSL-2750B devices contain a command injection vulnerability in the login.cgi component. Remote, unauthenticated attackers can execute arbitrary commands via the 'cli' parameter.

Affected products

  • D-Link DSL-2750B firmware before 1.05
  • D-Link DSL-2750B hardware

Timeline

  • 2016-02-11: disclosed: Initial public disclosure on Full Disclosure mailing list
  • 2022-10-19: other: NVD Published Date
  • 2024-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2016-2022: exploited: Exploited in the wild during this period