CVE-2019-16057 is a critical remote command injection vulnerability affecting the login_mgr.cgi script in D-Link DNS-320 devices, including firmware versions up to 2.05.B10. With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary commands with high impact on confidentiality, integrity, and availability. This flaw is actively exploited in the wild, listed in CISA's KEV catalog, and has high community discussion and media coverage, indicating significant risk despite no public Metasploit or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.05.b10CPE matchmatch criteria | cpe:2.3:o:dlink:dns-320_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.