CVE-2019-16057: D-Link DNS-320 Remote Code Execution Vulnerability
The loginmgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
Other sources
The loginmgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect affected D-Link DNS-320 devices from the network if still in use (the product is end-of-life).
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16057?
CVE-2019-16057 is classified as a critical vulnerability due to its potential for remote code execution.
How does CVE-2019-16057 affect D-Link DNS-320 devices?
CVE-2019-16057 allows remote attackers to execute arbitrary commands on D-Link DNS-320 devices running vulnerable firmware.
How do I fix CVE-2019-16057?
To mitigate CVE-2019-16057, update the firmware of the D-Link DNS-320 to the latest available version beyond 2.05.B10.
Is my D-Link DNS-320 device vulnerable to CVE-2019-16057?
Your D-Link DNS-320 device is vulnerable to CVE-2019-16057 if it is running firmware version 2.05.B10 or lower.
What is the impact of exploiting CVE-2019-16057?
Exploitation of CVE-2019-16057 can lead to unauthorized access and complete control over the affected D-Link DNS-320 device.