CVE-2020-10213: OS Command Injection
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wpsstaenrolleepin parameter in a setstaenrolleepin.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10213?
CVE-2020-10213 is a vulnerability that allows remote attackers to execute arbitrary commands on D-Link DIR-825 Rev.B 2.10 devices and TRENDnet TEW-632BRP 1.010B32.
How severe is CVE-2020-10213?
CVE-2020-10213 has a severity rating of 8.8 (critical).
How can remote attackers exploit CVE-2020-10213?
Remote attackers can exploit CVE-2020-10213 by sending a malicious POST request with a crafted wps_sta_enrollee_pin parameter to the set_sta_enrollee_pin.cgi script.
Which devices are affected by CVE-2020-10213?
D-Link DIR-825 Rev.B 2.10 devices and TRENDnet TEW-632BRP 1.010B32 are affected by CVE-2020-10213.
Are there any fixes or patches available for CVE-2020-10213?
At the moment, there are no official fixes or patches available for CVE-2020-10213. It is recommended to regularly check for updates from the vendors.