CVE-2016-20017: D-Link DSL-2750B Devices Command Injection Vulnerability
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
Other sources
D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DSL-2750Bto a version that resolves this vulnerability.Fixed in 1.05 - Remove
Remove
D-Link DSL-2750Bfrom your environment.Discontinue use of the product if mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2016-20017?
CVE-2016-20017 is considered a high severity vulnerability due to its potential for remote unauthenticated command injection.
How do I fix CVE-2016-20017?
To fix CVE-2016-20017, upgrade the D-Link DSL-2750B firmware to version 1.05 or later.
What devices are affected by CVE-2016-20017?
The D-Link DSL-2750B devices running firmware versions prior to 1.05 are affected by CVE-2016-20017.
Can CVE-2016-20017 be exploited remotely?
Yes, CVE-2016-20017 allows for remote exploitation without authentication.
What type of vulnerability is CVE-2016-20017?
CVE-2016-20017 is classified as a command injection vulnerability.