CVE-2020-25506
D-Link DNS-320 Device Command Injection Vulnerability
Record summary
CVE-2020-25506 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template. CISA lists CVE-2020-25506 in KEV.
Description
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Mar 15, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
DNS-320 DeviceBrowse D-Link / DNS-320 Device | CISA | Version data not supplied | |
DNS-320 Storage DeviceBrowse D-Link / DNS-320 Storage Device | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALD-Link DNS-320 - Unauthenticated Remote Code ExecutionCVSS 9.8
D-Link DNS-320 FW v2.06B01 Revision Ax is susceptible to a command injection vulnerability in a system_mgr.cgi component. The component does not successfully sanitize the value of the HTTP parameters f_ntp_server, which in turn leads to arbitrary command execution.
Impact
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary code on the affected device.
Remediation
Apply the latest firmware update provided by D-Link to mitigate this vulnerability.
Source: ProjectDiscovery