CISA Known Exploited Vulnerability (KEV)
D-Link DSL-2750B Devices Command Injection Vulnerability
January 8, 2024
January 29, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
References
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-77 |
Improper Neutralization of Special Elements used in a Command (‘Command Injection’) |