CVE-2016-20017Active Exploitation(dlink / dsl-2750b)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for dlink dsl-2750b systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.

7.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-01-29. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-77

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dsl-2750b
  • dsl-2750b_firmware

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • 8 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 3 signals
  • Technical details provided in 5 signals
  • General: 1 classified signal
  • Peaked 7d ago at 1 mentions (2026-04-06); latest day: 1
  • 8 total mentions across 8 days

Affected systems

Vendors
Products
dsl-2750bdsl-2750b_firmware

1 version affected across 2 products

Deep dive

Activity timeline8 mentions / 8d
00111Mentions · 2026-04-06: 1Mentions · 2026-04-10: 1Mentions · 2026-05-29: 1Mentions · 2026-06-17: 1Mentions · 2026-06-19: 1Mentions · 2026-07-13: 1Mentions · 2026-08-05: 1Mentions · 2026-08-30: 1PoC Mentioned / Linked · 2026-07-13: 1PoC Mentioned / Linked · 2026-08-05: 1PoC Mentioned / Linked · 2026-08-30: 1Exploit Tool / Code · 2026-04-10: 1Exploit Tool / Code · 2026-07-13: 1Exploit Tool / Code · 2026-08-05: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-05-29: 1Active Exploitation · 2026-07-13: 1Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-30: 1Technical Details · 2026-04-06: 1Technical Details · 2026-05-29: 1Technical Details · 2026-06-17: 1Technical Details · 2026-07-13: 1Technical Details · 2026-08-05: 104-0604-1005-2906-1706-1907-1308-0508-30
Signal classification3 categories
Active Exploitation
562.5%
Exploit
225.0%
General
112.5%
Classification over time
DateTotalLabels
2026-04-061
Active Exploitation1
2026-04-101
Exploit1
2026-05-291
Active Exploitation1
2026-06-171
Exploit1
2026-06-191
General1
2026-07-131
Active Exploitation1
2026-08-051
Active Exploitation1
2026-08-301
Active Exploitation1
Full discourse8 posts
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting D-Link DSL-2750B routers (CVE-2016-20017) to distribute #Mirai #Gafgyt #terrabot 2026-05-29 05:15:50 UTC Source IP: 149.167.22.232 🇦🇺 User-Agent: terrabot-owned-you IOCs: hxxp://140.233.190.47/dlink 140.233.190.47 🇺🇸 888120a95ae35c37f6c8e4047fac270d https://t.co/alwj1cyPBq

    Post summary

    The post reports a live RCE attempt targeting D‑Link DSL‑2750B routers (CVE‑2016‑20017) by Mirai/Terrabot trojans, providing source IP, user agent, and IOCs that confirm active exploitation in the wild.

    01043673
    1.7K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting D-Link DSL-2750B routers (CVE-2016-20017) 2026-08-04 10:27:46 UTC Source IP: 117.252.86.216 🇮🇳 IOCs: hxxp://196.251.121.142/a3f8d2/dlink.sh 196.251.121.142 bb8f534fbff5ee61a95af9c4740ae043 https://t.co/aCsnrcKV4F

    Post summary

    A real‑time RCE attempt against D‑Link DSL‑2750B routers (CVE‑2016‑20017) is reported, with a malicious script and related indicators. This indicates active exploitation in the wild.

    01010265
    1.7K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting D-Link DSL-2750B routers (CVE-2016-20017) 2026-07-13 12:12:15 UTC Source IP: 170.155.2.13 🇦🇷 IOCs: hxxp://83.142.209.46/a3f8d2/dlink.sh 83.142.209.46 🇳🇱 https://t.co/ruwwrbEkK2

    Post summary

    A malicious actor is actively exploiting CVE‑2016‑20017 on D‑Link DSL‑2750B routers, demonstrated by a downloadable shell script and a source IP; no patch information is present.

    01010255
    1.7K followersView on X
  • sicehice@sicehice
    Exploit

    #RCE attempt targeting D-Link DSL-2750B routers (CVE-2016-20017) 2026-04-10 20:20:59 UTC Source IP: 41.59.203.24 🇹🇿 IOCs: hxxp://85.11.167.101/mips hxxp://85.11.167.101/arm7 85.11.167.101 🇧🇬 91b53cf57587d85f6002cc653dcf2256 https://t.co/qgbgif2q9s

    Post summary

    The tweet reports an RCE attempt on D‑Link DSL‑2750B routers for CVE‑2016‑20017 and supplies potential exploit payload URLs, but offers no technical, patch, or active exploitation details.

    01010349
    1.7K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting D-Link DSL-2750B routers (CVE-2016-20017) 2026-04-06 19:53:42 UTC Source IP: 147.10.45.195 🇦🇺 IOCs: hxxp://37.48.254.120/arm7 37.48.254.120 🇷🇺 35d3ed6cc4921af4feafa5e460ad9775 https://t.co/WUt1oGTekU

    Post summary

    An attack attempt exploiting CVE-2016-20017 on D‑Link DSL‑2750B routers was observed, with indicators including a malicious URL and attacker IP, indicating active exploitation activity.

    00011335
    1.7K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting D-Link DSL-2750B routers (CVE-2016-20017) 2026-08-30 00:23:08 UTC Source IP: 134.209.215.49 🇺🇸 IOCs: hxxp://196.251.121.142/a3f8d2/kaizen.mips hxxp://196.251.121.142/a3f8d2/kaizen.mpsl 196.251.121.142 62962daa1b19bbcc2db10b7bfd531ea6 https://t.co/sZDOoovgru

    Post summary

    This post reports an RCE attempt against D-Link DSL-2750B routers (CVE-2016-20017) with payload URLs, indicating active exploitation in the wild.

    01000316
    1.7K followersView on X
  • sicehice@sicehice
    General

    #RCE attempt targeting D-Link DSL-2750B routers (CVE-2016-20017) 2026-06-19 14:23:00 UTC Source IP: 129.150.63.76 🇸🇬 IOCs: hxxp://109.104.153.60/sh 109.104.153.60 🇳🇱 3dec4ac0f967baf21748c3dbcd22d5fc https://t.co/zWRu3AAdzp

    Post summary

    A report of a recent remote code execution attempt targeting D‑Link DSL‑2750B routers citing CVE‑2016‑20017, with malicious IOCs presented but lacking concrete proof of exploitation or a functioning PoC.

    01000248
    1.7K followersView on X
  • sicehice@sicehice
    Exploit

    #RCE attempt targeting D-Link DSL-2750B routers (CVE-2016-20017) 2026-06-17 07:29:42 UTC Source IP: 85.189.104.60 🇬🇧 IOCs: hxxp://109.104.153.60/sh 109.104.153.60 🇳🇱 3dec4ac0f967baf21748c3dbcd22d5fc https://t.co/vo1cRWUQZ1

    Post summary

    The tweet reports an attempted remote code execution against D‑Link DSL‑2750B routers using CVE‑2016‑20017, providing malicious host indicators but no evidence of widespread exploitation or mitigation.

    00000170
    1.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdsl-2750b---
OSdlinkdsl-2750b_firmware---

Explore more