D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-20017
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10088