S4E just found a medium ssl lucky13 vulnerability scanner
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-16920 Scanner

CVE-2019-16920 scanner - Remote Code Execution (RCE) vulnerability in D-Link DIR-655C, DIR-866L, DIR-652, DHP-1565, DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-16920
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

D-Link is a popular brand among those who seek a reliable and efficient networking solution for their homes or offices. Among its products, the DIR-655C, DIR-866L, DIR-652, DHP-1565, DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825 are some of the most popular ones. These products are used as networking devices that establish and maintain connections between devices via Wi-Fi or Ethernet. They offer great convenience for users who need an efficient way to share files, access the internet, and establish stable connections.

One of the vulnerabilities that have been detected in these products is CVE-2019-16920. This vulnerability is caused by a flaw in the design of the PingTest device common gateway interface. Essentially, an attacker can exploit this vulnerability by sending an arbitrary input to the interface, which could lead to a command injection. This means that an attacker who successfully triggers the command injection could gain full access to the system.

When exploited, this vulnerability could lead to a complete system compromise. This means that attackers could gain access to sensitive information, such as personal data, intellectual property, or company secrets. It could also lead to a full network takeover, which could be catastrophic for companies that rely on it for their operations.

In conclusion, vulnerabilities such as CVE-2019-16920 highlight the importance of keeping all digital assets secure. With the advanced features of the s4e.io platform, users can get the information they need to protect against such vulnerabilities easily and quickly. Protecting digital assets should be a top priority for all individuals and companies, and the right tools and resources can make all the difference.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of these products should take the following precautions:

  • Keep the devices' firmware up to date
  • Disable remote management features if not needed
  • Limit the access to the common gateway interface
  • Install a firewall to detect and block malicious traffic
  • Use a VPN for secure remote access to the network

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.