First published: Wed Oct 19 2022(Updated: )
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DSL-2750B | ||
All of | ||
D-Link DSL-2750B | <1.05 | |
Dlink Dsl-2750b Firmware | ||
D-Link DSL-2750B | <1.05 | |
Dlink Dsl-2750b Firmware |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-20017 is considered a high severity vulnerability due to its potential for remote unauthenticated command injection.
To fix CVE-2016-20017, upgrade the D-Link DSL-2750B firmware to version 1.05 or later.
The D-Link DSL-2750B devices running firmware versions prior to 1.05 are affected by CVE-2016-20017.
Yes, CVE-2016-20017 allows for remote exploitation without authentication.
CVE-2016-20017 is classified as a command injection vulnerability.