← Vulnerability feed

Vulnerability record · CVE-2019-16920 · published 27 September 2019

CVE-2019-16920: D-Link router PingTest CGI command injection allows unauthenticated RCE

Dlink · Dir 655 Firmware

Multiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sanitization, resulting in OS command injection. Because the endpoint is reachable without authentication, an attacker on the network can execute commands as the device's web service user. The affected products are end-of-life, so no vendor fix is expected.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 100% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
10Affected product versions listed by NVD
9References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with CVSS 9.8, confirmed exploitation in CISA KEV, and no vendor patch because the products are end-of-life.

What it is

Multiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sanitization, resulting in OS command injection. Because the endpoint is reachable without authentication, an attacker on the network can execute commands as the device's web service user. The affected products are end-of-life, so no vendor fix is expected.

Impact

An attacker gains remote code execution on the device, leading to full system compromise of the router. That provides a foothold for traffic interception, credential capture, and use of the device as a pivot into the internal network.

Attack surface

Reached over the network via the device's web management interface, specifically the PingTest CGI endpoint. The CVSS vector shows PR:N and UI:N, so no authentication and no user interaction are required.

Exploitation

CVE-2019-16920 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25) and has an EPSS 30-day probability of 0.99996, with public exploit references tagged on the record. No ransomware campaign use is documented.

What to do

  • Retire or replace the affected end-of-life D-Link models; CISA's required action is to disconnect them if still in use.
  • If a device cannot be removed immediately, isolate it on a dedicated network segment with no access to management interfaces from untrusted networks.
  • Block external and lateral access to the router web management interface and the PingTest CGI endpoint at the firewall.
  • Disable remote administration and UPnP on these devices, and change default administrative credentials.
  • Monitor for and remove any of the listed models still present on the network inventory.

Detection

  • Inspect web server or proxy logs for requests to the PingTest CGI path containing shell metacharacters such as semicolons, pipes, backticks, or command substitution.
  • Alert on outbound connections from router management IPs to unusual destinations or ports, which may indicate command execution and callback.
  • Watch for unexpected processes or configuration changes on the device, such as new admin accounts or altered DNS settings.
  • Scan the network for the affected D-Link models and flag any that remain reachable on management interfaces.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-16920 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "D-Link Multiple Routers Command Injection Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 April 2022.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-16920 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-8361Realtek SDK miniigd SOAP service remote code executionThe miniigd SOAP service in the Realtek SDK fails to properly validate input in a NewInternalClient request, allowing remote code execution. The flaw…KEVEPSS 100%analysed10.0CVE-2018-25115Dlink dir-110 firmware os command injection vulnerabilityMultiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vuln…EPSS 10%9.8CVE-2021-42627D-Link DIR-615 WAN page exposed without authenticationThe WAN configuration page wan.htm on D-Link DIR-615 devices running firmware 20.06 is reachable directly without authentication. An unauthenticated …EPSS 63%analysed9.8CVE-2021-37388Dlink dir-615 firmware classic buffer overflow vulnerabilityA buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver …EPSS 3.7%9.8CVE-2019-13560Dlink dir-655 firmware vulnerabilityD-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi setup_wizard parameter.EPSS 3.6%9.8CVE-2019-13561Dlink dir-655 firmware os command injection vulnerabilityD-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_c…EPSS 8.4%9.8CVE-2018-15839D-Link DIR-615 router buffer overflow via long Authorization headerD-Link DIR-615 firmware contains a memory buffer overflow (CWE-119) triggered by an overly long Authorization HTTP header. The flaw is remotely reach…EPSS 45%analysed8.8CVE-2019-17525Dlink dir-615 firmware improper restriction of authentication attempts vulnerabilityThe login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.EPSS 5.8%

Source: NIST National Vulnerability Database (record CVE-2019-16920), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.