First published: Tue Feb 02 2021(Updated: )
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DNS-320 Storage Device | ||
All of | ||
D-Link DNS-320 | =2.06b01 | |
D-Link DNS-320L | =ax | |
D-Link DNS-320 | =2.06b01 | |
D-Link DNS-320L | =ax |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25506 has a high severity rating due to the potential for remote arbitrary code execution.
To fix CVE-2020-25506, update the D-Link DNS-320 firmware to the latest version that addresses this vulnerability.
CVE-2020-25506 specifically affects D-Link DNS-320 devices running firmware version 2.06B01.
CVE-2020-25506 is classified as a command injection vulnerability.
Yes, CVE-2020-25506 can be exploited remotely, allowing attackers to execute arbitrary commands on the affected D-Link devices.