← Back

CVE-2019-16920

Published: Sep 27, 2019Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

Affected (10)

10 products
Dir 655 Firmware
Dir 866l Firmware
Dir 652 Firmware
Dhp 1565 Firmware
Dir 855l Firmware
Dap 1533 Firmware
Dir 862l Firmware
Dir 615 Firmware
Dir 835 Firmware
Dir 825 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.02b05
Running on/withPlatform Versions
Dlink
Dir 655
Version cx
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.03b04
Running on/withPlatform Versions
Dlink
Dir 866l
Version ax
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dlink
Dir 652
Version ax
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.01
Running on/withPlatform Versions
Dlink
Dhp 1565
Version ax
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dlink
Dir 855l
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dlink
Dap 1533
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dlink
Dir 862l
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dlink
Dir 615
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dlink
Dir 835
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Dlink
Dir 825
All versions

References (9)

Source: cve@mitre.org
Broken LinkThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.