D-Link Routers Unauthenticated...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Introduction In September 2019, Fortinet's FortiGuard Labs discovered and reported an unauthenticated command injection vulnerability ([FG-VD-19-117](https://fortiguard.com/zeroday/FG-VD-19-117)/[CVE-2019-16920](https://nvd.nist.gov/vuln/detail/CVE-2019-16920)) in D-Link products that could lead to Remote Code Execution (RCE) upon successful exploitation. We rated this as a critical issue since the vulnerability can be triggered remotely without authentication. Based on our findings, the vulnerability was found in latest firmware of the following D-Link products: - DIR-655 - DIR-866L - DIR-652 - DHP-1565 At the time of the writing of this advisory, these products are at End of Life (EOL) support, which means the vendor will not provide fixes for the issue we discovered. FortiGuard Labs appreciates the vendor’s quick response, and we recommend that users upgrade to a new device series as soon as possible. ### Vulnerability Details The vulnerability begins with a bad...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息