Vulnerability record · CVE-2019-20500 · published 5 March 2020
CVE-2019-20500: D-Link DWL-2600AP web interface OS command injection
Dlink · Dwl 2600ap Firmware
The D-Link DWL-2600AP (firmware 4.2.0.15 Rev A) web interface fails to sanitize shell metacharacters in the configBackup or downloadServerip parameter of admin.cgi?action=config_save, allowing OS command injection. An attacker who can reach the management interface with valid credentials can execute arbitrary commands on the device.
Description
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows authenticated command execution and is in CISA KEV with very high EPSS, but requires access to the management interface and valid credentials.
What it is
The D-Link DWL-2600AP (firmware 4.2.0.15 Rev A) web interface fails to sanitize shell metacharacters in the configBackup or downloadServerip parameter of admin.cgi?action=config_save, allowing OS command injection. An attacker who can reach the management interface with valid credentials can execute arbitrary commands on the device.
Impact
An authenticated attacker gains arbitrary OS command execution on the access point, enabling full compromise of the device, data theft, and use as a pivot into the network.
Attack surface
Reached through the device web management interface via the Save Configuration function; the CVSS vector (AV:L/PR:L/UI:N) indicates local access and low privileges with no user interaction, though the description states authentication is required.
Exploitation
CVE-2019-20500 is listed in CISA KEV (added 2023-06-29) and has an EPSS 30-day probability of 0.97109 (99.9th percentile); a public Exploit-DB proof of concept is referenced. No ransomware campaign use is documented.
What to do
- Apply the vendor patch per D-Link advisory SAP10113, or discontinue use of the product if no update is available.
- Restrict management interface access to trusted administrative networks and disable remote/web management exposure to untrusted segments.
- Change default administrative credentials and enforce strong unique passwords on the device.
- Segment or isolate access points on a dedicated management VLAN to limit lateral movement if compromised.
- Monitor D-Link advisory and CISA KEV guidance for updated remediation instructions.
Detection
- Inspect web server and device logs for requests to admin.cgi?action=config_save containing shell metacharacters in configBackup or downloadServerip.
- Monitor for unexpected outbound connections or processes spawned on the access point that indicate command execution.
- Alert on authentication events to the device management interface from unusual source addresses or at anomalous times.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-20500 to the Known Exploited Vulnerabilities catalog on 29 June 2023 as "D-Link DWL-2600AP Access Point Command Injection Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 20 July 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10113 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/46841 | ExploitThird Party AdvisoryVDB Entry |
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10113 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/46841 | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-20500 | US Government Resource |
Track CVE-2019-20500 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-20500), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.