Executive brief
Multiple D-Link routers are vulnerable to unauthenticated remote command injection via the PingTest gateway interface. Attackers can exploit this by sending arbitrary input to the device, potentially leading to full system compromise.
Affected products
- D-Link DIR-655C
- D-Link DIR-866L
- D-Link DIR-652
- D-Link DHP-1565
- D-Link DIR-855L
- D-Link DAP-1533
- D-Link DIR-862L
- D-Link DIR-615
- D-Link DIR-835
- D-Link DIR-825
Timeline
- 2019-10-01: disclosed: Initial analysis by NIST
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog