← לוח פגיעויות

CVE-2019-16920

קריטית 9.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
D-Link Multiple Routers Command Injection Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
The impacted product is end-of-life and should be disconnected if still in use.

תיאור (מקור, אנגלית)

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
100% (אחוזון 100) נכון ל-4/8/2026
CWE
CWE-78

מוצרים מושפעים

dlink: dir-655 firmware; dlink: dir-655; dlink: dir-866l firmware; dlink: dir-866l; dlink: dir-652 firmware; dlink: dir-652; dlink: dhp-1565 firmware; dlink: dhp-1565; dlink: dir-855l firmware; dlink: dir-855l; dlink: dap-1533 firmware; dlink: dap-1533; dlink: dir-862l firmware; dlink: dir-862l; dlink: dir-615 firmware

קישורים