CVE-2019-16920
KEVHIGH 10.0EPSS 100.0%
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-03-25
- Nuclei
- critical · CWE-78
- Published
- 2019-09-27
- Updated
- 2025-10-21
Proof-of-concept exploits (1)
- eniac888/CVE-2019-16920-MassPwn3r1★ · 2019-10-15
Nuclei templates (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/dlink-cve-2019-16920-rce.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2019/CVE-2019-16920.yaml