CVE-2019-16057
CRITICALCVSS 9.8/10Actively ExploitedEPSS 87.21%
Last modified
CVE-2019-16057 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.. CISA has confirmed active exploitation in the wild. EPSS estimates a 87.21% chance of exploitation in the next 30 days.
Description
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dns-320 Firmware | <= 2.05.b10 |
References
- https://blog.cystack.net/d-link-dns-320-rce/Exploit, Third Party Advisory
- https://www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdfThird Party Advisory, US Government Resource
- https://blog.cystack.net/d-link-dns-320-rce/Exploit, Third Party Advisory
- https://www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdfThird Party Advisory, US Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16057US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2019-16057?
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
How severe is CVE-2019-16057?
CVE-2019-16057 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 87.21% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2019-16057?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-16028A vulnerability in the web-based management interface of Cis…9.8
- CVE-2019-16029A vulnerability in the application programming interface (AP…9.1
- CVE-2019-1603A vulnerability in the CLI of Cisco NX-OS Software could all…7.8
- CVE-2019-1604A vulnerability in the user account management interface of …7.8
- CVE-2019-1605A vulnerability in the NX-API feature of Cisco NX-OS Softwar…7.8
- CVE-2019-16056An issue was discovered in Python through 2.7.16, 3.x throug…7.5
- CVE-2019-16058An issue was discovered in the pam_p11 component 0.2.0 and 0…
- CVE-2019-16059Sentrifugo 3.2 lacks CSRF protection. This could lead to an …
- CVE-2019-1606A vulnerability in the CLI of Cisco NX-OS Software could all…7.8
- CVE-2019-16060The Airbrake Ruby notifier 4.2.3 for Airbrake mishandles the…
- CVE-2019-16061A number of files on the NETSAS Enigma NMS server 65.0.0 and…8.8
- CVE-2019-16062NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitiv…6.5
Are you affected by CVE-2019-16057?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
