CVE-2019-16057criticalunder attackransomwareCWE-78

CVE-2019-16057

Published · Updated

95Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 86%
from disclosure to weapon
Published on NVDSep 16
CISA KEV+942d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-05-06

The impacted product is end-of-life and should be disconnected if still in use.

In short

The login manager script in D-Link DNS-320 devices allows attackers to run arbitrary commands on the device without authentication. This gives complete control over the storage device and its data.

Technical detail

The login_mgr.cgi endpoint is vulnerable to OS command injection (CWE-78) via improper input validation. An unauthenticated remote attacker can inject shell commands through user-controlled parameters, leading to arbitrary code execution with device privileges. Affected versions: D-Link DNS-320 through 2.05.B10.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a