Skip to content
COOEY

EXPOSURES › CVE-2016-20017

CVE-2016-20017

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-20017 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildsupply-chainunpatched

D-Link DSL-2750B devices allow remote, unauthenticated command injection via login.cgi, enabling arbitrary code execution.

This vulnerability permits remote attackers to execute arbitrary commands on D-Link DSL-2750B devices without authentication, creating a critical RCE risk for CMMC environments. D-Link's history of unpatched RCEs in consumer firmware makes this a high-priority supply chain failure that could compromise sensitive data or enable lateral movement in defense-industrial-base networks.

Shame score — A remote, unauthenticated RCE in a widely deployed consumer router that has been actively exploited, reflecting D-Link's pattern of critical firmware vulnerabilities.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.