CVE-2016-20017: D-Link DSL-2750B Devices Command Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-01-08. EPSS: 64.2% chance of exploitation in the next 30 days.
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
Affected products
- D-Link DSL-2750B Firmware: before 1.05 (fixed in 1.05)
Published 2022-10-19. Last modified 2026-06-17.