LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2019-16920

CVE-2019-16920

D-Link Multiple Routers Command Injection Vulnerability

CVSS 9.8 · CRITICAL ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2022-03-25. Federal remediation due 2022-04-15.
Required action: The impacted product is end-of-life and should be disconnected if still in use.

Summary

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

CVSS 3.1 breakdown

Base score9.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Dlink dir-655 firmwareDlink dir-655Dlink dir-866l firmwareDlink dir-866lDlink dir-652 firmwareDlink dir-652Dlink dhp-1565 firmwareDlink dhp-1565Dlink dir-855l firmwareDlink dir-855lDlink dap-1533 firmwareDlink dap-1533Dlink dir-862l firmwareDlink dir-862lDlink dir-615 firmwareDlink dir-615Dlink dir-835 firmwareDlink dir-835Dlink dir-825 firmwareDlink dir-825
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2025-11-07. Always verify against the vendor advisory before acting.

Scroll to Top