.. / CVE-2019-16057

Exploit for D-Link DNS-320 - Remote Code Execution (CVE-2019-16057)

Description:

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

Nuclei Template

View the template here CVE-2019-16057.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-16057.yaml
Copy

References:

https://www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdf
https://nvd.nist.gov/vuln/detail/CVE-2019-16057
https://web.archive.org/web/20201222035258im_/https://blog.cystack.net/content/images/2019/09/poc.png
https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
https://github.com/Z0fhack/Goby_POC