Skip to content
COOEY

EXPOSURES › CVE-2020-25367

CVE-2020-25367

CRITICAL
DETAIL
SourceNVD · cve Published2021-11-04 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-25367 ↗
⚡ RCE SHAME 50/100 rce

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
D-Link's command injection flaw in DIR-823G firmware was widely flagged as critical, with active exploitation by threat actors and CISA warnings, indicating severe security fallout and vendor accounta
dailysecurityreview.com ↗ severe-fallout -0.90
Active exploitation and CISA warning
"TP-Link Router Vulnerabilities Actively Exploited by Hackers, CISA Urges Immediate Disconnection"
cooey ↗ severe-fallout -0.90
Critical vulnerability disclosed
"A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login."
www.databreachtoday.com ↗ severe-fallout +0.00
Irrelevant to D-Link
"Hidden Backdoor in Tenda Router Firmware - DataBreachToday"
The Hacker News ↗ severe-fallout +0.00
Irrelevant to D-Link
"Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot"
app.opencve.io ↗ severe-fallout +0.00
Irrelevant to D-Link
"CVEs and Security Vulnerabilities - OpenCVE"
dailysecurityreview.com ↗ severe-fallout +0.00
Irrelevant to D-Link
"ASUS Patches Critical Authentication Bypass Vulnerability in DSL Series Routers"
www.cvefind.com ↗ severe-fallout +0.00
Irrelevant to D-Link
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.