CRITICAL
CVE-2016-20017
CVSS
9.8
KEV
Description
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
Summary dbcve.org
D-Link DSL-2750B devices running firmware prior to version 1.05 contain a command injection vulnerability in the cli parameter of the login.cgi endpoint, allowing remote unauthenticated attackers to execute arbitrary commands on the device. The flaw has been actively exploited in the wild from 2016 through 2022.
Mitigation
Upgrade affected DSL-2750B devices to firmware version 1.05 or later; if the device is no longer supported, replace it and restrict remote management access (e.g., disable WAN-side HTTP administration) until replacement.
Weakness (CWE)
CWE-77
Command Injection
EPSS Score
65.23%
Probability of exploitation in next 30 days
99.2th percentile
References
https://seclists.org/fulldisclosure/2016/Feb/53
Exploit, Mailing List, Third Party Advisory
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10088
Patch, Vendor Advisory
https://www.exploit-db.com/exploits/44760
Exploit, Third Party Advisory, VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-20017
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.