EXPOSURES › CVE-2020-25368
CVE-2020-25368
CRITICAL
DETAIL
SourceNVD · cve
Published2021-11-04
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-25368 ↗
⚡ RCE
SHAME 50/100
rce
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.50
D-Link faced significant scrutiny for the command injection vulnerability in DIR-823G devices, with the vulnerability being tracked by multiple security databases and potentially impacting CISA KEV li
Neutral
"A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05."
Negative
"Hidden Backdoor in Tenda Router Firmware - DataBreachToday"
Neutral
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
Neutral
"Fines Database — GDPR Enforcement Tracker"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.