CVE-2020-25759

HIGH

D-Link DSR Unified Services Router Firmware < 3.17 - Authenticated OS Command Injection via Multipart HTTP POST Request

Title source: llm
STIX 2.1

Description

An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.

References (3)

Core 3

Scores

CVSS v3 8.8
EPSS 0.0145
EPSS Percentile 81.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78 CWE-20
Status published
Products (10)
dlink/dsr-1000_firmware < 3.17
dlink/dsr-1000ac_firmware < 3.17
dlink/dsr-1000n_firmware < 3.17
dlink/dsr-150_firmware < 3.17
dlink/dsr-150n_firmware < 3.17
dlink/dsr-250_firmware < 3.17
dlink/dsr-250n_firmware < 3.17
dlink/dsr-500_firmware < 3.17
dlink/dsr-500ac_firmware < 3.17
dlink/dsr-500n_firmware
Published Dec 15, 2020
Tracked Since Feb 18, 2026