Junglewise Threat Intelligence

CVE-2020-25506: D-Link DNS-320 Device Command Injection Vulnerability

CVE-2020-25506 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: D-Link.

Executive brief

The D-Link DNS-320 device contains an OS command injection vulnerability in the system_mgr.cgi component. Remote attackers can exploit this flaw to execute arbitrary code on the affected device without authentication.

Affected products

  • D-Link DNS-320 Firmware 2.06B01 Revision Ax

Timeline

  • 2021-02-02: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: External advisory publication date