CVE-2016-20017: D-Link DSL-2750B Devices Command Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-01-08. EPSS: 64.2% chance of exploitation in the next 30 days.

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.

Affected products

  • D-Link DSL-2750B Firmware: before 1.05 (fixed in 1.05)

Published 2022-10-19. Last modified 2026-06-17.