CVE-2019-20500: D-Link DWL-2600AP Access Point
EPSS96.7%No. 323 of 1739 in KEV
CVE year2019~4 yrs before listing
Same vendor in KEV26
Same product1
| Field | Value |
|---|---|
| Vendor | D-Link |
| Product | DWL-2600AP Access Point |
| Name | D-Link DWL-2600AP Access Point Command Injection Vulnerability |
| Added to KEV | 2023-06-29 |
| US federal due date | 2023-07-20 |
| Ransomware use | Unknown |
| CWE | CWE-78 |
CISA description
D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A D-Link DWL-2600AP Access Point vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-29.