EXPOSURES › CVE-2016-20017
CVE-2016-20017
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link DSL-2750B devices allow remote, unauthenticated command injection via login.cgi, enabling arbitrary code execution.
This vulnerability permits remote attackers to execute arbitrary commands on D-Link DSL-2750B devices without authentication, creating a critical RCE risk for CMMC environments. D-Link's history of unpatched RCEs in consumer firmware makes this a high-priority supply chain failure that could compromise sensitive data or enable lateral movement in defense-industrial-base networks.
Shame score — A remote, unauthenticated RCE in a widely deployed consumer router that has been actively exploited, reflecting D-Link's pattern of critical firmware vulnerabilities.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.