CVE-2020-25506: D-Link DNS-320 Device Command Injection Vulnerability
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the systemmgr.cgi component, which can lead to remote arbitrary code execution.
Other sources
D-Link DNS-320 device contains a command injection vulnerability in the sytemmgr.cgi component that may allow for remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25506?
CVE-2020-25506 has a high severity rating due to the potential for remote arbitrary code execution.
How do I fix CVE-2020-25506?
To fix CVE-2020-25506, update the D-Link DNS-320 firmware to the latest version that addresses this vulnerability.
What devices are affected by CVE-2020-25506?
CVE-2020-25506 specifically affects D-Link DNS-320 devices running firmware version 2.06B01.
What type of vulnerability is CVE-2020-25506?
CVE-2020-25506 is classified as a command injection vulnerability.
Can CVE-2020-25506 be exploited remotely?
Yes, CVE-2020-25506 can be exploited remotely, allowing attackers to execute arbitrary commands on the affected D-Link devices.