← back
CVE-2020-9377

CVE-2020-9377

CVSS 8.8 HIGHEPSS 21.3%● KEVCWE-78
Vexday Risk Score
56Attention
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 8.8EPSS 21.3%KEV simPoC Nuclei Metasploit Patch
Lifecycle
09 Jul 2020Published on NVD
25 Mar 2022Active exploitation (CISA KEV)
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

D-Link DIR-610 routers have a flaw that allows attackers to run arbitrary commands remotely by sending specially crafted requests to the device. This is critical because it gives attackers complete control over the router, compromising all network traffic.

Technical detail

Remote command injection vulnerability in D-Link DIR-610's command.php endpoint where the 'cmd' parameter is not properly sanitized, allowing unauthenticated or authenticated attackers to execute arbitrary OS commands with device privileges. Attack vector is network-based via HTTP/HTTPS, and impacts devices no longer receiving security updates.

Summary generated and translated by AI from the official description.
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →