Junglewise Threat Intelligence

CVE-2020-9377: D-Link DIR-610 Devices Remote Command Execution

CVE-2020-9377 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-25

Vendors: D-Link.

Executive brief

D-Link DIR-610 devices are vulnerable to remote command execution via the 'cmd' parameter in command.php. This OS command injection vulnerability allows authenticated attackers to execute arbitrary commands on the underlying operating system.

Affected products

  • D-Link DIR-610 firmware -
  • D-Link DIR-610 hardware -

Timeline

  • 2020-07-09: disclosed: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog