Vulnerability record · CVE-2019-16057 · published 16 September 2019
CVE-2019-16057: D-Link DNS-320 login_mgr.cgi OS command injection
Dlink · Dns 320 Firmware
The login_mgr.cgi script in D-Link DNS-320 firmware through 2.05.B10 fails to neutralize input passed to a system command, allowing OS command injection. The device is end-of-life, so no vendor fix is expected and exposed units remain permanently at risk.
Description
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution on an end-of-life device that is in CISA KEV with confirmed ransomware use and very high EPSS.
What it is
The login_mgr.cgi script in D-Link DNS-320 firmware through 2.05.B10 fails to neutralize input passed to a system command, allowing OS command injection. The device is end-of-life, so no vendor fix is expected and exposed units remain permanently at risk.
Impact
An unauthenticated attacker can execute arbitrary commands on the device, gaining full control of the NAS and any data or credentials it holds.
Attack surface
Reachable over the network via HTTP requests to login_mgr.cgi; the CVSS vector shows no privileges or user interaction required.
Exploitation
Listed in CISA KEV since 2022-04-15 with known ransomware campaign use, and EPSS probability is 0.87 (99.7th percentile); a public exploit reference exists.
What to do
- Retire or replace the end-of-life DNS-320; no patched firmware is available per CISA guidance.
- If it must stay online temporarily, disconnect it from the internet and restrict management access to a trusted internal segment.
- Block external access to login_mgr.cgi and the device's web management interface at the perimeter.
- Monitor for and rotate any credentials or data stored on the device, assuming compromise if it was internet-exposed.
Detection
- Inspect web logs for requests to /cgi-bin/login_mgr.cgi containing shell metacharacters or command strings.
- Alert on unexpected outbound connections or processes spawned by the device's web server.
- Hunt for known exploit payload patterns against login_mgr.cgi in IDS/IPS and proxy telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-16057 to the Known Exploited Vulnerabilities catalog on 15 April 2022 as "D-Link DNS-320 Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 6 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.cystack.net/d-link-dns-320-rce/ | ExploitThird Party Advisory |
| https://www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdf | Third Party AdvisoryUS Government Resource |
| https://blog.cystack.net/d-link-dns-320-rce/ | ExploitThird Party Advisory |
| https://www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdf | Third Party AdvisoryUS Government Resource |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16057 | US Government Resource |
Track CVE-2019-16057 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-16057), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.