D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
2022-10-19T05:15:08.817
2025-03-14T20:00:42.390
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dsl-2750b_firmware | < 1.05 | Yes |
Hardware | dlink | dsl-2750b | - | No |