CRITICAL

CVE-2016-20017

Dlink Dsl 2750b Firmware 2022-10-19 CVSS v3.1
CVSS
9.8
KEV

Description

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.

Summary dbcve.org

D-Link DSL-2750B devices running firmware prior to version 1.05 contain a command injection vulnerability in the cli parameter of the login.cgi endpoint, allowing remote unauthenticated attackers to execute arbitrary commands on the device. The flaw has been actively exploited in the wild from 2016 through 2022.

Mitigation

Upgrade affected DSL-2750B devices to firmware version 1.05 or later; if the device is no longer supported, replace it and restrict remote management access (e.g., disable WAN-side HTTP administration) until replacement.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-77 Command Injection

EPSS Score

65.23%
Probability of exploitation in next 30 days
99.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE