CVE-2020-12774

HIGH

D-Link DSL-7740C - Command Injection

Title source: llm
STIX 2.1

Description

D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary command.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-3802-27204-1.html

Scores

CVSS v3 8.2
EPSS 0.0058
EPSS Percentile 69.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
dlink/dsl-7740c_firmware v6.tr069.20180723
Published Jul 22, 2020
Tracked Since Feb 18, 2026