CVE-2020-9377
CVE-2020-9377
Vexday Risk Score
56Attention
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 8.8EPSS 21.3%KEV simPoC —Nuclei —Metasploit —Patch —
Lifecycle
09 Jul 2020Published on NVD
25 Mar 2022Active exploitation (CISA KEV)
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short
D-Link DIR-610 routers have a flaw that allows attackers to run arbitrary commands remotely by sending specially crafted requests to the device. This is critical because it gives attackers complete control over the router, compromising all network traffic.
Technical detail
Remote command injection vulnerability in D-Link DIR-610's command.php endpoint where the 'cmd' parameter is not properly sanitized, allowing unauthenticated or authenticated attackers to execute arbitrary OS commands with device privileges. Attack vector is network-based via HTTP/HTTPS, and impacts devices no longer receiving security updates.
Summary generated and translated by AI from the official description.
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →