Junglewise Threat Intelligence

CVE-2019-16057: D-Link DNS-320 Remote Code Execution Vulnerability

CVE-2019-16057 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-15

Vendors: D-Link.

Executive brief

The login_mgr.cgi script in D-Link DNS-320 devices is vulnerable to remote command injection, allowing an unauthenticated attacker to execute arbitrary code via the network. The vulnerability stems from improper neutralization of special elements used in an OS command.

Affected products

  • D-Link DNS-320 firmware through 2.05.B10
  • D-Link DNS-320

Timeline

  • 2019-09-16: disclosed: NVD Published Date
  • 2022-04-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-06: other: CISA Due Date for remediation