CVE-2020-9377: D-Link DIR-610 Devices Remote Command Execution
UNSUPPORTED WHEN ASSIGNED D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Other sources
D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect D-Link DIR-610 devices from the network if still in use (the impacted product is end-of-life); isolate the devices from all networks to prevent remote exploitation via the cmd parameter to command.php.
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9377?
CVE-2020-9377 is classified as a critical vulnerability due to its potential for remote command execution on affected D-Link DIR-610 devices.
How do I fix CVE-2020-9377?
To mitigate CVE-2020-9377, it is recommended to replace the D-Link DIR-610 devices with models that receive ongoing support and security updates.
Which devices are affected by CVE-2020-9377?
CVE-2020-9377 affects D-Link DIR-610 devices specifically running outdated firmware that is no longer supported.
Can CVE-2020-9377 be exploited remotely?
Yes, CVE-2020-9377 allows for remote command execution, making it possible for an attacker to exploit the vulnerability from a remote location.
Is there a patch available for CVE-2020-9377?
There is no patch available for CVE-2020-9377 since the affected devices are no longer supported by D-Link.