LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-16920: D-Link Multiple Routers Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-16920 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.

CVE-2019-16920 is a command injection vulnerability affecting multiple D-Link routers. According to CISA, it can allow attackers to achieve full system compromise on impacted devices. Because these products are end-of-life, organizations still running them face ongoing risk if the devices remain reachable.

IT and security teams should treat any remaining instances as high priority for discovery and removal. Confirm all product-specific details against the vendor advisory and CISA guidance before acting.

How it works

This flaw is classed as CWE-78, OS command injection. In this weakness class, an application passes unsanitized or insufficiently validated input into a system command shell. An attacker who can reach the vulnerable interface may supply crafted input that the device interprets as additional operating-system commands.

On network devices such as routers, successful abuse of command injection commonly leads to arbitrary command execution with the privileges of the vulnerable process. CISA states that exploitation of this vulnerability can result in full system compromise. Exact attack vectors, required authentication state, and request formats are not detailed in the supplied facts; teams must verify those mechanics in the vendor advisory rather than assuming any particular exploit path.

Am I affected? How to find it in your systems

D-Link routers of this class typically appear at the network edge as customer-premises equipment, small-office/home-office gateways, or legacy branch devices. They may still be present in lab networks, forgotten remote sites, or secondary internet connections.

How to remediate

CISA’s required action is clear: the impacted product is end-of-life and should be disconnected if still in use. Replacement with a currently supported router is the primary remediation path.

If you can't patch immediately

Because the product is end-of-life, long-term reliance on compensating controls is not a substitute for disconnection. Use the following only as temporary risk reduction:

If your data may have been exposed

Actively exploited vulnerabilities on network devices can lead to full compromise and subsequent data exposure or lateral movement. Known ransomware use is not documented for this CVE in the supplied facts. If the device may have been reachable by attackers, examine downstream systems for signs of follow-on activity, rotate credentials that traversed the router, and review any sensitive traffic that passed through it. You can run a free exposure scan of your email addresses against known breach data sets to check whether associated accounts appear in prior breaches while you complete containment and replacement.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · Multiple Routers
WeaknessCWE-78
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities