EXPOSURES › CVE-2016-11021
CVE-2016-11021
HIGH ⌖ ON CISA KEV · EXPLOITEDA remote attacker can execute arbitrary OS commands on D-Link DCS-930L devices via the setSystemCommand function.
This OS command injection flaw allows remote code execution, enabling attackers to compromise the device and potentially pivot to other systems. DIB organizations must ensure all D-Link hardware is patched or replaced, as the vendor has a history of unpatched RCE vulnerabilities that violate CMMC supply chain security requirements.
Shame score — D-Link repeatedly ships unpatched RCE vulnerabilities in consumer firmware, demonstrating a negligent security posture that directly threatens CMMC compliance and supply chain integrity.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.