EXPOSURES › CVE-2019-16920
CVE-2019-16920
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link routers had a command injection flaw allowing full system compromise.
D-Link routers contained a command injection vulnerability enabling attackers to execute arbitrary commands and achieve full system compromise. This is a critical failure for DIB organizations relying on D-Link networking hardware, as it represents an unpatched, actively exploited vulnerability that could lead to network infiltration and data exfiltration. Organizations must ensure all D-Link routers are patched and monitored for signs of exploitation.
Shame score — A command injection vulnerability in widely deployed routers that was actively exploited in the wild, representing a severe, avoidable failure in vendor security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.