Critical severity9.8CISA KEVNVD Advisory· Published Sep 27, 2019· Updated Jun 17, 2026
CVE-2019-16920
CVE-2019-16920
Description
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21- cpe:2.3:o:dlink:dap-1533_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:dlink:dir-615_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:dlink:dir-652_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:dlink:dir-825_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:dlink:dir-835_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:dlink:dir-855l_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:dlink:dir-862l_firmware:-:*:*:*:*:*:*:*
- D-Link/DIR-655Cdescription
Patches
Vulnerability mechanics
References
5- medium.com/%4080vul/determine-the-device-model-affected-by-cve-2019-16920-by-zoomeye-bf6fec7f9bb3nvdExploitThird Party Advisory
- www.seebug.org/vuldb/ssvid-98079nvdExploitThird Party Advisory
- fortiguard.com/zeroday/FG-VD-19-117nvdBroken LinkThird Party Advisory
- www.kb.cert.org/vuls/id/766427nvdThird Party AdvisoryUS Government Resource
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
1- RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning ExploitsTrend Micro Research · Oct 9, 2025