CVE-2020-18568: OS Command Injection
Published Feb 2, 2021
·Updated
The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.
Affected Software
4 affected components
Dlink Dsr-250 Firmware=3.14
Dlink Dsr-250
Dlink Dsr-1000n Firmware=2.11b201
Dlink Dsr-1000n
Event History
Feb 2, 2021
CVE Published
via MITRE·01:22 PM
Data Sourced
via MITRE·01:22 PM
Description
Frequently Asked Questions
1
What is CVE-2020-18568?
CVE-2020-18568 is a command injection vulnerability in the D-Link DSR-250 (3.14) and DSR-1000N (2.11B201) UPnP service.
2
What is the severity of CVE-2020-18568?
The severity of CVE-2020-18568 is critical with a severity score of 9.8.
3
How can CVE-2020-18568 be exploited?
CVE-2020-18568 can be exploited by sending a specially crafted UPnP request, allowing remote command execution.
4
What is affected by CVE-2020-18568?
The D-Link DSR-250 (3.14) and DSR-1000N (2.11B201) devices with UPnP service enabled are affected by CVE-2020-18568.
5
How do I fix CVE-2020-18568?
To fix CVE-2020-18568, update the firmware of the affected D-Link DSR-250 and DSR-1000N devices to the latest version.