Skip to content
COOEY

EXPOSURES › CVE-2016-11021

CVE-2016-11021

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-11021 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

A remote attacker can execute arbitrary OS commands on D-Link DCS-930L devices via the setSystemCommand function.

This OS command injection flaw allows remote code execution, enabling attackers to compromise the device and potentially pivot to other systems. DIB organizations must ensure all D-Link hardware is patched or replaced, as the vendor has a history of unpatched RCE vulnerabilities that violate CMMC supply chain security requirements.

Shame score — D-Link repeatedly ships unpatched RCE vulnerabilities in consumer firmware, demonstrating a negligent security posture that directly threatens CMMC compliance and supply chain integrity.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.