Vulnerability record · CVE-2019-16920 · published 27 September 2019
CVE-2019-16920: D-Link router PingTest CGI command injection allows unauthenticated RCE
Dlink · Dir 655 Firmware
Multiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sanitization, resulting in OS command injection. Because the endpoint is reachable without authentication, an attacker on the network can execute commands as the device's web service user. The affected products are end-of-life, so no vendor fix is expected.
Description
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with CVSS 9.8, confirmed exploitation in CISA KEV, and no vendor patch because the products are end-of-life.
What it is
Multiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sanitization, resulting in OS command injection. Because the endpoint is reachable without authentication, an attacker on the network can execute commands as the device's web service user. The affected products are end-of-life, so no vendor fix is expected.
Impact
An attacker gains remote code execution on the device, leading to full system compromise of the router. That provides a foothold for traffic interception, credential capture, and use of the device as a pivot into the internal network.
Attack surface
Reached over the network via the device's web management interface, specifically the PingTest CGI endpoint. The CVSS vector shows PR:N and UI:N, so no authentication and no user interaction are required.
Exploitation
CVE-2019-16920 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25) and has an EPSS 30-day probability of 0.99996, with public exploit references tagged on the record. No ransomware campaign use is documented.
What to do
- Retire or replace the affected end-of-life D-Link models; CISA's required action is to disconnect them if still in use.
- If a device cannot be removed immediately, isolate it on a dedicated network segment with no access to management interfaces from untrusted networks.
- Block external and lateral access to the router web management interface and the PingTest CGI endpoint at the firewall.
- Disable remote administration and UPnP on these devices, and change default administrative credentials.
- Monitor for and remove any of the listed models still present on the network inventory.
Detection
- Inspect web server or proxy logs for requests to the PingTest CGI path containing shell metacharacters such as semicolons, pipes, backticks, or command substitution.
- Alert on outbound connections from router management IPs to unusual destinations or ports, which may indicate command execution and callback.
- Watch for unexpected processes or configuration changes on the device, such as new admin accounts or altered DNS settings.
- Scan the network for the affected D-Link models and flag any that remain reachable on management interfaces.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-16920 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "D-Link Multiple Routers Command Injection Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 15 April 2022.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/zeroday/FG-VD-19-117 | Broken LinkThird Party Advisory |
| https://medium.com/%4080vul/determine-the-device-model-affected-by-cve-2019-16920-by-zoomeye-bf6fec7f9bb3 | ExploitThird Party Advisory |
| https://www.kb.cert.org/vuls/id/766427 | Third Party AdvisoryUS Government Resource |
| https://www.seebug.org/vuldb/ssvid-98079 | ExploitThird Party Advisory |
| https://fortiguard.com/zeroday/FG-VD-19-117 | Broken LinkThird Party Advisory |
| https://medium.com/%4080vul/determine-the-device-model-affected-by-cve-2019-16920-by-zoomeye-bf6fec7f9bb3 | ExploitThird Party Advisory |
| https://www.kb.cert.org/vuls/id/766427 | Third Party AdvisoryUS Government Resource |
| https://www.seebug.org/vuldb/ssvid-98079 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16920 | US Government Resource |
Track CVE-2019-16920 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-16920), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.