Record summary

CVE-2020-9377 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2020-9377 in KEV.

Description

D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Mar 25, 2022 · CISA
VulnCheck KEV
Listed · Nov 11, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 3, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubrenatoalencar/dlink-dir610-exploitsRepository PoCby renatoalencarStars: 4Not analyzed3 files

1.2 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

5