Record summary

CVE-2020-25506 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template. CISA lists CVE-2020-25506 in KEV.

Description

D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Mar 15, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALD-Link DNS-320 - Unauthenticated Remote Code ExecutionCVSS 9.8

D-Link DNS-320 FW v2.06B01 Revision Ax is susceptible to a command injection vulnerability in a system_mgr.cgi component. The component does not successfully sanitize the value of the HTTP parameters f_ntp_server, which in turn leads to arbitrary command execution.

Impact

Successful exploitation of this vulnerability allows remote attackers to execute arbitrary code on the affected device.

Remediation

Apply the latest firmware update provided by D-Link to mitigate this vulnerability.

WeaknessesCWE-78
Authorsgy741
Template tagscvecve2020dlinkrceoastmiraiunauthrouterkevvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:dlink:dns-320_firmware:2.06b01:*:*:*:*:*:*:*
Shodan: http.html:"sharecenter"
FOFA: body="sharecenter"

Source: ProjectDiscovery

References

5