CVE-2020-25757

HIGH

D-Link DSR VPN Routers < 3.17 - Unauthenticated OS Command Injection via Lua CGI

Title source: llm
STIX 2.1

Description

A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with firmware 3.14 and 3.17.

References (3)

Core 3

Scores

CVSS v3 8.8
EPSS 0.0052
EPSS Percentile 66.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78 CWE-20
Status published
Products (10)
dlink/dsr-1000_firmware < 3.17
dlink/dsr-1000ac_firmware < 3.17
dlink/dsr-1000n_firmware < 3.17
dlink/dsr-150_firmware < 3.17
dlink/dsr-150n_firmware < 3.17
dlink/dsr-250_firmware < 3.17
dlink/dsr-250n_firmware < 3.17
dlink/dsr-500_firmware < 3.17
dlink/dsr-500ac_firmware < 3.17
dlink/dsr-500n_firmware
Published Dec 15, 2020
Tracked Since Feb 18, 2026