D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dsl 2750b
HWDlinkall versionsDlink Dsl 2750b Firmware
OSDlink< 1.05
CISA KEV — detailsi
- Vendori
- D-Link
- Producti
- DSL-2750B Devices
- Added to KEVi
- January 8, 2024
- Remediation deadline (US Federal)i
- January 29, 2024(overdue)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.
Related vulnerabilities
D-Link DNS-320L/325/327L/340L — zakodowane na stałe poświadczenia (hard-coded credentials)
Command Injection w D-Link DIR-820L umożliwiający eskalację uprawnień do root
Buffer overflow w D-Link Go-RT-AC750 via cgibin/hnap_main — RCE bez uwierzytelnienia
RCE w D-Link DIR-820L — command injection przez HTTP POST
RCE w routerach D-Link via DDNS — funkcja w pliku binarnym ncc2