Vulnerability Description
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dsl-2750B Firmware | < 1.05 |
| Dlink | Dsl-2750B | - |
Related Weaknesses (CWE)
References
- https://seclists.org/fulldisclosure/2016/Feb/53ExploitMailing ListThird Party Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP1PatchVendor Advisory
- https://www.exploit-db.com/exploits/44760ExploitThird Party AdvisoryVDB Entry
- https://seclists.org/fulldisclosure/2016/Feb/53ExploitMailing ListThird Party Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP1PatchVendor Advisory
- https://www.exploit-db.com/exploits/44760ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-US Government Resource
FAQ
What is CVE-2016-20017?
CVE-2016-20017 is a vulnerability with a CVSS score of 9.8 (CRITICAL). D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
How severe is CVE-2016-20017?
CVE-2016-20017 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-20017?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dsl-2750B Firmware, Dlink Dsl-2750B.