CVE Feed

    Dashboard / CVE / CVE-2019-16920

    CVE-2019-16920

    Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

    Published:Sep 27, 2019
    Last Modified:Nov 7, 2025
    EPS:Sep 27, 2019
    EPSS Score:0.94174
    CVSS Score:9.8

    CISA Notification

    Description

    Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

    Required Action:

    The impacted product is end-of-life and should be disconnected if still in use.

    Notes:

    No extra notes provided.

    Due Date
    Apr 15, 2022
    1610 days ago
    Alert Date
    Mar 25, 2022
    1631 days ago

    Affected Products

    Vendor
    Dlink
    Product
    Dap-1533
    Vendor
    Dlink
    Product
    Dap-1533 Firmware
    Vendor
    Dlink
    Product
    Dhp-1565
    Vendor
    Dlink
    Product
    Dhp-1565 Firmware
    Vendor
    Dlink
    Product
    Dir-615
    Vendor
    Dlink
    Product
    Dir-615 Firmware
    Vendor
    Dlink
    Product
    Dir-652
    Vendor
    Dlink
    Product
    Dir-652 Firmware
    Vendor
    Dlink
    Product
    Dir-655
    Vendor
    Dlink
    Product
    Dir-655 Firmware
    Vendor
    Dlink
    Product
    Dir-825
    Vendor
    Dlink
    Product
    Dir-825 Firmware
    Vendor
    Dlink
    Product
    Dir-835
    Vendor
    Dlink
    Product
    Dir-835 Firmware
    Vendor
    Dlink
    Product
    Dir-855l
    Vendor
    Dlink
    Product
    Dir-855l Firmware
    Vendor
    Dlink
    Product
    Dir-862l
    Vendor
    Dlink
    Product
    Dir-862l Firmware
    Vendor
    Dlink
    Product
    Dir-866l
    Vendor
    Dlink
    Product
    Dir-866l Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High