CVE-2020-25368: OS Command Injection
Published Nov 4, 2021
·Updated
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
Affected Software
4 affected components
Dlink Dir-823g Firmware=1.02b05
Dlink Dir-823g=a1
All of the following
Dlink Dir-823g Firmware=1.02b05
Dlink Dir-823g=a1
Event History
Nov 4, 2021
CVE Published
via MITRE·10:19 AM
Data Sourced
via MITRE·10:19 AM
Description
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-25368?
CVE-2020-25368 is a command injection vulnerability discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05.
2
How does CVE-2020-25368 affect D-Link DIR-823G devices?
CVE-2020-25368 allows an attacker to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
3
Which software versions are affected by CVE-2020-25368?
D-Link DIR-823G devices with firmware V1.0.2B05 are affected by CVE-2020-25368.
4
What is the severity of CVE-2020-25368?
CVE-2020-25368 has a severity rating of 9.8 (Critical).
5
How can I fix CVE-2020-25368?
To fix CVE-2020-25368, update your D-Link DIR-823G device firmware to a version that is not vulnerable.