CVE-2016-11021
published 2020-03-09CVE-2016-11021: setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
PriorityP185high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
68.53%
99.3th percentile
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dcs-930l_firmware | < 2.12 | 2.12 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP requests targeting the /setSystemCommand endpoint on D-Link DCS-930L devices for OS command injection payloads in the SystemCommand parameter. ↗
- →Alert on any authenticated POST/GET to /setSystemCommand containing shell metacharacters or command separators in the SystemCommand parameter value. ↗
- ·Exploitation requires valid credentials; unauthenticated access to the endpoint is not sufficient — monitor for brute-force or credential-stuffing activity preceding exploitation attempts. ↗
- ·Only firmware versions prior to 2.12 are vulnerable; devices running 2.12 or later are not affected. End-of-life devices should be disconnected if patching is not possible. ↗
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck7.2HIGH
cisa7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q7vj-25p7-w99v: setSystemCommand on D-Link DCS-930L devices before 2
ghsa_unreviewed·2022-05-24
CVE-2016-11021 [HIGH] CWE-78 GHSA-q7vj-25p7-w99v: setSystemCommand on D-Link DCS-930L devices before 2
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
VulnCheck
D-Link DCS-930L Devices OS Command Injection Vulnerability
vulncheck·2016·CVSS 7.2
CVE-2016-11021 [HIGH] CWE-78 D-Link DCS-930L Devices OS Command Injection Vulnerability
D-Link DCS-930L Devices OS Command Injection Vulnerability
setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
Affected: D-Link DCS-930L Devices
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Exploitation References: https://cybersecurity.att.com/blogs/labs-research/att-alien-labs-finds-new-golang-malwarebotenago-targeting-millions-of-routers-and-iot-devices-with-more-than-30-exploits; https://cybersecurity.att.com/blogs/labs-research/botenago-strike-again-malware-source-code-uploaded-to-github; https://www.fortiguard.com/threat-signal-report/4389/botenago-malware-targets-multiple-iot-devices; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://
CISA
D-Link DCS-930L Devices OS Command Injection Vulnerability
cisa·2022-03-25·CVSS 7.2
CVE-2016-11021 [HIGH] CWE-78 D-Link DCS-930L Devices OS Command Injection Vulnerability
Vulnerability: D-Link DCS-930L Devices OS Command Injection Vulnerability
Affected: D-Link DCS-930L Devices
setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-11021
Remediation Due Date: 2022-04-15
No detection rules found.
No writeups or analysis indexed.
2020-03-09
Published
2022-03-25
Added to CISA KEV
Exploited in the wild