CVE-2019-16920 is an unauthenticated remote code execution vulnerability affecting numerous D-Link router models, including DIR-655C, DIR-866L, and DIR-855L. Attackers can exploit a common injection flaw in the "PingTest" device common gateway interface by sending arbitrary input, leading to full system compromise. This critical vulnerability has a CVSS score of 9.8, indicating a network-based attack with low complexity and high impact on confidentiality, integrity, and availability. It is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered significant community attention with available Nuclei templates and numerous media reports.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.02b05CPE matchmatch criteria | cpe:2.3:o:dlink:dir-655_firmware:*:*:*:*:*:*:*:* | ||
<= 1.03b04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-866l_firmware:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dir-652_firmware:-:*:*:*:*:*:*:* | ||
<= 1.01CPE matchmatch criteria | cpe:2.3:o:dlink:dhp-1565_firmware:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dir-855l_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.