← Vulnerability feed

Vulnerability record · CVE-2019-16057 · published 16 September 2019

CVE-2019-16057: D-Link DNS-320 login_mgr.cgi OS command injection

Dlink · Dns 320 Firmware

The login_mgr.cgi script in D-Link DNS-320 firmware through 2.05.B10 fails to neutralize input passed to a system command, allowing OS command injection. The device is end-of-life, so no vendor fix is expected and exposed units remain permanently at risk.

9.8 CVSS 3.1 Critical CISA KEV since 15 Apr 2022 Known ransomware use EPSS 86% · top 0.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
86%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution on an end-of-life device that is in CISA KEV with confirmed ransomware use and very high EPSS.

What it is

The login_mgr.cgi script in D-Link DNS-320 firmware through 2.05.B10 fails to neutralize input passed to a system command, allowing OS command injection. The device is end-of-life, so no vendor fix is expected and exposed units remain permanently at risk.

Impact

An unauthenticated attacker can execute arbitrary commands on the device, gaining full control of the NAS and any data or credentials it holds.

Attack surface

Reachable over the network via HTTP requests to login_mgr.cgi; the CVSS vector shows no privileges or user interaction required.

Exploitation

Listed in CISA KEV since 2022-04-15 with known ransomware campaign use, and EPSS probability is 0.87 (99.7th percentile); a public exploit reference exists.

What to do

  • Retire or replace the end-of-life DNS-320; no patched firmware is available per CISA guidance.
  • If it must stay online temporarily, disconnect it from the internet and restrict management access to a trusted internal segment.
  • Block external access to login_mgr.cgi and the device's web management interface at the perimeter.
  • Monitor for and rotate any credentials or data stored on the device, assuming compromise if it was internet-exposed.

Detection

  • Inspect web logs for requests to /cgi-bin/login_mgr.cgi containing shell metacharacters or command strings.
  • Alert on unexpected outbound connections or processes spawned by the device's web server.
  • Hunt for known exploit payload patterns against login_mgr.cgi in IDS/IPS and proxy telemetry.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-16057 to the Known Exploited Vulnerabilities catalog on 15 April 2022 as "D-Link DNS-320 Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 6 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-16057 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-3272D-Link NAS Devices Hard-Coded Credentials in nas_sharing.cgiD-Link DNS and DNR series NAS devices contain hard-coded credentials reachable through the HTTP GET handler in /cgi-bin/nas_sharing.cgi, where the 'u…KEVEPSS 98%analysed9.8CVE-2024-3273D-Link legacy NAS command injection in nas_sharing.cgiAn unauthenticated command injection flaw exists in the HTTP GET request handler of /cgi-bin/nas_sharing.cgi on multiple end-of-life D-Link NAS model…KEVEPSS 100%analysed9.8CVE-2020-25506D-Link DNS-320 system_mgr.cgi command injectionD-Link DNS-320 firmware v2.06B01 Revision Ax contains an OS command injection flaw in the system_mgr.cgi component, allowing remote arbitrary code ex…KEVEPSS 100%analysed9.2CVE-2024-10914D-Link NAS account_mgr.cgi OS command injection via name parameterD-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L NAS devices up to firmware 20241028 contain an OS command injection in the cgi_user_add function of /…EPSS 96%analysed9.2CVE-2024-10915D-Link DNS-320/325/340L NAS account_mgr.cgi OS command injectionThe cgi_user_add function in /cgi-bin/account_mgr.cgi on D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L NAS devices fails to sanitize the group argu…EPSS 80%analysed8.7CVE-2024-7832Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS…EPSS 2.1%8.7CVE-2024-7831Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L…EPSS 1.8%8.7CVE-2024-7829Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2019-16057), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.