PT-2020-6492 · D Link · D-Link Dns-320
Swing
+1
·
Published
2020-07-16
·
Updated
2025-12-01
·
CVE-2020-25506
CVSS v2.0
10
Critical
| AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DNS-320 FW version 2.06B01 Revision Ax
Description
The issue is related to command injection in the system mgr.cgi component, which can lead to remote arbitrary code execution. This occurs due to errors in neutralizing special elements in the OS command. The exploitation of this issue can allow a remote attacker to execute arbitrary code.
Recommendations
For D-Link DNS-320 FW version 2.06B01 Revision Ax, consider disabling the system mgr.cgi component as a temporary workaround until a patch is available. Restrict access to this component to minimize the risk of exploitation.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dns-320