First published: Thu Nov 04 2021(Updated: )
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-823g Firmware | =1.02b05 | |
Dlink Dir-823g | =a1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25368 is a command injection vulnerability discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05.
CVE-2020-25368 allows an attacker to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
D-Link DIR-823G devices with firmware V1.0.2B05 are affected by CVE-2020-25368.
CVE-2020-25368 has a severity rating of 9.8 (Critical).
To fix CVE-2020-25368, update your D-Link DIR-823G device firmware to a version that is not vulnerable.