Critical severity9.8CISA KEVNVD Advisory· Published Oct 19, 2022· Updated Jun 17, 2026
CVE-2016-20017
CVE-2016-20017
Description
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
4- supportannouncement.us.dlink.com/announcement/publication.aspxnvdPatchVendor Advisory
- seclists.org/fulldisclosure/2016/Feb/53nvdExploitMailing ListThird Party Advisory
- www.exploit-db.com/exploits/44760nvdExploitThird Party AdvisoryVDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
1- What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)SANS Internet Storm Center · Jun 25, 2026