CVE-2019-16057
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
The impacted product is end-of-life and should be disconnected if still in use.
The login manager script in D-Link DNS-320 devices allows attackers to run arbitrary commands on the device without authentication. This gives complete control over the storage device and its data.
The login_mgr.cgi endpoint is vulnerable to OS command injection (CWE-78) via improper input validation. An unauthenticated remote attacker can inject shell commands through user-controlled parameters, leading to arbitrary code execution with device privileges. Affected versions: D-Link DNS-320 through 2.05.B10.
The full analysis of this CVE is available in Portuguese →