CISA KEV · catalog date Mar 25, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2019-16920
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.
Exploited in the wild (CISA KEV since Mar 25, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 100.0% exploit likelihood as of Jul 18, 2026.
As of Aug 27, 2026
Normalized restatement
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
- State
- PUBLISHED
- Published
- Sep 27, 2019
- Updated
- Oct 21, 2025
- Evidence coverage
- 98%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmitreOriginal evidence ↗
Record text: Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
Inspect raw assertion
- Field
container- Value
- Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: D-Link Multiple Routers Command Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- D-Link Multiple Routers Command Injection Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 100% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999960000000; percentile 0.999880000000
FIRST EPSS · score date Jul 18, 2026 · 100th percentile · first observed Jul 19, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
Inspect raw assertion
- Field
container- Value
- Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.
D-Link Multiple Routers Command Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- D-Link Multiple Routers Command Injection Vulnerability
100% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999960000000; percentile 0.999880000000
Applicability
Cited product scope
Grouped from 20 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
21 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-944ae52bda9b7f9d3ebb8779680aebb4b71e554a3cf1b5c69c7b144580e53217Linked exactInspect raw assertion
cpe:2.3:h:dlink:dap-1533:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0d3e4627-940f-4859-bc67-b6229bc0afd8
product-385304baa36b0b733637efec6463750bb47c1639da9c2f99528bea74d94090ebLinked exactInspect raw assertion
cpe:2.3:o:dlink:dap-1533_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
db7d656d-47b5-4269-a155-741d60f818cd
product-ba4884cb60ec28fa81d05910fcc55ac36c3efe0f89ffcd2f10e39051e0b3c5f7Linked exactInspect raw assertion
cpe:2.3:h:dlink:dhp-1565:ax:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bafb86ea-966b-4db3-9b81-198878d76573
product-b7ccee0aa338f6ea232c9d0a802ff2a84e4ea8aa873987161d20705cf26f3286Linked exactInspect raw assertion
cpe:2.3:o:dlink:dhp-1565_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 1.01
- Match ID
369d2c8e-89f1-4e03-8da0-ba2db1245569
product-7691da32d16409774bb644de301b27953477e691e341089fe36ce7f4861cecfeLinked exactInspect raw assertion
cpe:2.3:h:dlink:dir-615:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2e92e959-c211-4979-a233-163befcf6f0d
product-cd6952af38e2b71ede81fa7fa67c1989a08967a3ff2d2bb3e2c6bb03b647b104Linked exactInspect raw assertion
cpe:2.3:o:dlink:dir-615_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8c55e6d4-820d-469f-a343-635a621c0d7c
product-1c5c758e266c579c55994451d4b00cec3dfad5cf7f916b610ac1d78bb97b29e9Linked exactInspect raw assertion
cpe:2.3:h:dlink:dir-652:ax:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2e4d52d3-71fd-4d29-881a-393b35f3db65
product-48bba9f900e5d8f4d18d605449d121e3f5fbc5ec85256ddc17dc1ff804c97a94Linked exactInspect raw assertion
cpe:2.3:o:dlink:dir-652_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1147272f-0f23-4606-a84e-ca971414c65b
product-a1b0e138ecdf68b7c784cc4cc8d98758a31fda5c3b60a96e7092fc6ac4ef7c45Linked exactInspect raw assertion
cpe:2.3:h:dlink:dir-655:cx:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8f90f9e0-0f90-4afd-868c-370882c47248
product-34256f20d3381d1bf50b1ad14d2e3297983053c8d4b412c5bc0f8cd89e7f30ecLinked exactInspect raw assertion
cpe:2.3:o:dlink:dir-655_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 3.02b05
- Match ID
525853b4-1c30-4d96-ad4f-26fd77469b33
product-a160323af677f381782d1f16864b1dadd6d54aa8b47856b2841e6c921027e285Linked exactInspect raw assertion
cpe:2.3:h:dlink:dir-825:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7038f8a9-03f3-4442-b371-84801ef05447
product-3dff354d6596a95d8b10337c46163f00dddf793f7bd3e1fc335193fbe6a3d820Linked exactInspect raw assertion
cpe:2.3:o:dlink:dir-825_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eec49da6-d1f4-4a2a-904e-907356f3c804
product-5da35e7e1b84df347ee83ed3e1bfcb38e97798a0a69fdae26e25ec8912f2f81aLinked exactInspect raw assertion
cpe:2.3:h:dlink:dir-835:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d1b91013-e79e-4076-916d-d52d6e417ea7
product-0094436740548e0ed33845b60ed0c707bd7ef851d3883243d6ee5eaa7af10803Linked exactInspect raw assertion
cpe:2.3:o:dlink:dir-835_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fcfe0993-c19a-4c60-b8c6-e549d748537a
product-10cc110c71ed3698494b30e544d4c2739ae6ad9e57019999c5561da705448c0aLinked exactInspect raw assertion
cpe:2.3:h:dlink:dir-855l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7eb62bc4-69bc-40d7-a8e7-f5728b827250
product-66a2d8b94fe469b5ac1741c1598208cdce0641c698ac1760c41c325c31687e08Linked exactInspect raw assertion
cpe:2.3:o:dlink:dir-855l_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
239f0015-2834-4dbb-b115-58871d0ff764
product-a65f7bba48684a36401e2ca573fcf47a607eb0bc226bd3ac16f1142099e8b697Linked exactInspect raw assertion
cpe:2.3:h:dlink:dir-862l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0552e33f-bb39-4701-b91a-1db33992505c
product-6633adc956a11e8eeb94c0782d211c6bcd143949facc200c1d49c3118e9d41baLinked exactInspect raw assertion
cpe:2.3:o:dlink:dir-862l_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
380a4761-5474-4f52-a4ee-62844d5ee82c
product-e9650e20d5f5d590a10082b7b81962a1eb490718d60a6adaa2ec5e32e121e538Linked exactInspect raw assertion
cpe:2.3:h:dlink:dir-866l:ax:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
52177d2b-d7f8-4351-a169-fdf6a5fbf44d
product-890df189187a8dec7ad71c1079bb642dc326932a1dae0f4908d2852112ae00efLinked exactInspect raw assertion
cpe:2.3:o:dlink:dir-866l_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 1.03b04
- Match ID
ea174575-0468-4ab1-a504-b5aa559d3219
Affected-product evidence
Accepted scope and product mapping
10 canonical links · 1 source-reported links
vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-0094436740548e0ed33845b60ed0c707bd7ef851d3883243d6ee5eaa7af10803
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ef26e881-f234-445a-bd97-38a34f7e98c3vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-34256f20d3381d1bf50b1ad14d2e3297983053c8d4b412c5bc0f8cd89e7f30ec
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1b1173e7-b73f-489e-9131-1e3bafea9a7avendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-385304baa36b0b733637efec6463750bb47c1639da9c2f99528bea74d94090eb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f4fd39d2-2135-483b-ad07-ce37cbf66484vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-3dff354d6596a95d8b10337c46163f00dddf793f7bd3e1fc335193fbe6a3d820
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5a8d3d7c-759f-4059-a95f-26e6b4f5045evendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-48bba9f900e5d8f4d18d605449d121e3f5fbc5ec85256ddc17dc1ff804c97a94
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8bbb1faf-6c02-4d81-948a-ff09d51e2c3avendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-6633adc956a11e8eeb94c0782d211c6bcd143949facc200c1d49c3118e9d41ba
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d8852f5b-4c80-4052-b88e-cc1f88c95d4avendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-66a2d8b94fe469b5ac1741c1598208cdce0641c698ac1760c41c325c31687e08
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
354f3b31-f214-42a5-a3e6-1b32db76afb4vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-890df189187a8dec7ad71c1079bb642dc326932a1dae0f4908d2852112ae00ef
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
43906566-56f9-4216-a170-e75e3195eb14vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-b7ccee0aa338f6ea232c9d0a802ff2a84e4ea8aa873987161d20705cf26f3286
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cbf5fce3-82b8-40dc-951d-e97bd0430747vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-cd6952af38e2b71ede81fa7fa67c1989a08967a3ff2d2bb3e2c6bb03b647b104
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ec57e5e4-dd02-4928-8dbc-c3328895e929Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9ed50c11-f68d-4977-943a-94d08c15dc64Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.