← Vulnerability feed

Vulnerability record · CVE-2016-20017 · published 19 October 2022

CVE-2016-20017: D-Link DSL-2750B login.cgi command injection

Dlink · Dsl 2750b Firmware

D-Link DSL-2750B firmware before 1.05 passes the login.cgi cli parameter to a shell without sanitization, allowing command injection. The flaw is remotely reachable without authentication and has been exploited in the wild from 2016 through 2022, making it a persistent risk for any device still running vulnerable firmware.

9.8 CVSS 3.1 Critical CISA KEV since 8 Jan 2024 EPSS 64% · top 0.8% CWE-77 · Command injection
9.8CVSS 3.1 base score
64%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated remote command injection, confirmed in-the-wild exploitation, and CISA KEV listing with a past remediation due date.

What it is

D-Link DSL-2750B firmware before 1.05 passes the login.cgi cli parameter to a shell without sanitization, allowing command injection. The flaw is remotely reachable without authentication and has been exploited in the wild from 2016 through 2022, making it a persistent risk for any device still running vulnerable firmware.

Impact

An unauthenticated attacker can execute arbitrary commands on the router, gaining full control of the device and its network position. This enables traffic interception, credential theft, and use of the device as a pivot or botnet node.

Attack surface

Reachable over the network via the login.cgi endpoint with the cli parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The device must expose its web management interface to the attacker, which is typical for internet-facing or LAN-adjacent deployments.

Exploitation

Listed in CISA KEV with a 2024-01-29 remediation due date and referenced by public exploit entries, confirming active exploitation. EPSS 30-day probability is 0.652 (99.2nd percentile), indicating high likelihood of attempted exploitation.

What to do

  • Upgrade DSL-2750B firmware to 1.05 or later per D-Link advisory SAP10088; if no supported firmware exists, discontinue use of the device.
  • Remove the device's web management interface from internet exposure and restrict administrative access to trusted internal networks only.
  • Isolate the router on a segmented network or replace it with a supported model if patching is not possible.
  • Monitor vendor end-of-life notices and retire unsupported D-Link DSL-2750B units from production.
  • Apply network-level filtering to block external access to login.cgi and other management endpoints.

Detection

  • Inspect HTTP request logs for POST or GET requests to /login.cgi containing shell metacharacters (;, |, `, $()) in the cli parameter.
  • Monitor router or upstream firewall logs for outbound connections to unusual destinations originating from the DSL-2750B management IP.
  • Alert on unexpected processes or command execution on the device if host-level telemetry is available.
  • Correlate IDS/IPS signatures for known D-Link DSL-2750B command injection exploit patterns with device management traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2016-20017 to the Known Exploited Vulnerabilities catalog on 8 January 2024 as "D-Link DSL-2750B Devices Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 29 January 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-20017 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed8.7CVE-2025-4008Meteobridge web interface command injection without authenticationThe Meteobridge web interface, built from CGI shell scripts and C, exposes an endpoint vulnerable to command injection. Because the endpoint also lac…KEVEPSS 94%analysed6.1CVE-2025-59689Libraesva ESG command injection via compressed email attachmentLibraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachme…KEVEPSS 1.9%analysed9.8CVE-2025-10035Fortra GoAnywhere MFT License Servlet deserialization to command injectionThe License Servlet in Fortra GoAnywhere MFT deserializes untrusted data, and an attacker who can present a validly forged license response signature…KEVEPSS 100%analysed8.8CVE-2020-25079D-Link DCS cameras authenticated command injection in ddns_enc.cgiD-Link DCS-2530L (before 1.06.01 Hotfix) and DCS-2670L (through 2.02) contain an authenticated command injection flaw in cgi-bin/ddns_enc.cgi. A user…KEVEPSS 54%analysed

Source: NIST National Vulnerability Database (record CVE-2016-20017), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.