CRITICAL · 9.8

CVE-2019-16920

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device co...

Vulnerability Description

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DlinkDir-655 Firmware<= 3.02b05
DlinkDir-655cx
DlinkDir-866L Firmware<= 1.03b04
DlinkDir-866Lax
DlinkDir-652 Firmware-
DlinkDir-652ax
DlinkDhp-1565 Firmware<= 1.01
DlinkDhp-1565ax
DlinkDir-855L Firmware-
DlinkDir-855L-
DlinkDap-1533 Firmware-
DlinkDap-1533-
DlinkDir-862L Firmware-
DlinkDir-862L-
DlinkDir-615 Firmware-
DlinkDir-615-
DlinkDir-835 Firmware-
DlinkDir-835-
DlinkDir-825 Firmware-
DlinkDir-825-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-16920?

CVE-2019-16920 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device co...

How severe is CVE-2019-16920?

CVE-2019-16920 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-16920?

Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dir-655 Firmware, Dlink Dir-655, Dlink Dir-866L Firmware, Dlink Dir-866L, Dlink Dir-652 Firmware.