Executive brief
The D-Link DNS-320 device contains an OS command injection vulnerability in the system_mgr.cgi component. Remote attackers can exploit this flaw to execute arbitrary code on the affected device without authentication.
Affected products
- D-Link DNS-320 Firmware 2.06B01 Revision Ax
Timeline
- 2021-02-02: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: External advisory publication date