Vulnerability record · CVE-2016-20017 · published 19 October 2022
CVE-2016-20017: D-Link DSL-2750B login.cgi command injection
Dlink · Dsl 2750b Firmware
D-Link DSL-2750B firmware before 1.05 passes the login.cgi cli parameter to a shell without sanitization, allowing command injection. The flaw is remotely reachable without authentication and has been exploited in the wild from 2016 through 2022, making it a persistent risk for any device still running vulnerable firmware.
Description
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated remote command injection, confirmed in-the-wild exploitation, and CISA KEV listing with a past remediation due date.
What it is
D-Link DSL-2750B firmware before 1.05 passes the login.cgi cli parameter to a shell without sanitization, allowing command injection. The flaw is remotely reachable without authentication and has been exploited in the wild from 2016 through 2022, making it a persistent risk for any device still running vulnerable firmware.
Impact
An unauthenticated attacker can execute arbitrary commands on the router, gaining full control of the device and its network position. This enables traffic interception, credential theft, and use of the device as a pivot or botnet node.
Attack surface
Reachable over the network via the login.cgi endpoint with the cli parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The device must expose its web management interface to the attacker, which is typical for internet-facing or LAN-adjacent deployments.
Exploitation
Listed in CISA KEV with a 2024-01-29 remediation due date and referenced by public exploit entries, confirming active exploitation. EPSS 30-day probability is 0.652 (99.2nd percentile), indicating high likelihood of attempted exploitation.
What to do
- Upgrade DSL-2750B firmware to 1.05 or later per D-Link advisory SAP10088; if no supported firmware exists, discontinue use of the device.
- Remove the device's web management interface from internet exposure and restrict administrative access to trusted internal networks only.
- Isolate the router on a segmented network or replace it with a supported model if patching is not possible.
- Monitor vendor end-of-life notices and retire unsupported D-Link DSL-2750B units from production.
- Apply network-level filtering to block external access to login.cgi and other management endpoints.
Detection
- Inspect HTTP request logs for POST or GET requests to /login.cgi containing shell metacharacters (;, |, `, $()) in the cli parameter.
- Monitor router or upstream firewall logs for outbound connections to unusual destinations originating from the DSL-2750B management IP.
- Alert on unexpected processes or command execution on the device if host-level telemetry is available.
- Correlate IDS/IPS signatures for known D-Link DSL-2750B command injection exploit patterns with device management traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-20017 to the Known Exploited Vulnerabilities catalog on 8 January 2024 as "D-Link DSL-2750B Devices Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 29 January 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://seclists.org/fulldisclosure/2016/Feb/53 | ExploitMailing ListThird Party Advisory |
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10088 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44760 | ExploitThird Party AdvisoryVDB Entry |
| https://seclists.org/fulldisclosure/2016/Feb/53 | ExploitMailing ListThird Party Advisory |
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10088 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44760 | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-20017 | US Government Resource |
Track CVE-2016-20017 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-20017), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.