CVE-2020-25506
CRITICAL(9.8)KEVWahrscheinlich ausgenutzt
D-Link DNS-320 Device Command Injection Vulnerability
Beschreibung
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
KEV-Informationen
CVSS-Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnenBetroffene Produkte
| Hersteller | Produkt | Version |
|---|---|---|
| dlink | dns-320 firmware | 2.06b01 |
Mehrere CVSS-Bewertungen
Quelle: [email protected](Primary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Referenzen
- https://gist.github.com/WinMin/6f63fd1ae95977e0e2d49bd4b5f00675(Exploit, Third Party Advisory)
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10183(Vendor Advisory)
- https://www.dlink.com/en/security-bulletin/(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-25506(US Government Resource)
Hilfe beim Schwachstellenmanagement?
Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.