Skip to content
COOEY

EXPOSURES › CVE-2020-25368

CVE-2020-25368

CRITICAL
DETAIL
SourceNVD · cve Published2021-11-04 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-25368 ↗
⚡ RCE SHAME 50/100 rce

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.50
D-Link faced significant scrutiny for the command injection vulnerability in DIR-823G devices, with the vulnerability being tracked by multiple security databases and potentially impacting CISA KEV li
CISA ↗ severe-fallout -0.40
Severe-fallout
"ICS Advisories | CISA"
cooey ↗ severe-fallout -0.30
Neutral
"A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05."
www.databreachtoday.com ↗ severe-fallout -0.20
Negative
"Hidden Backdoor in Tenda Router Firmware - DataBreachToday"
www.cvefind.com ↗ severe-fallout +0.00
Neutral
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
classactionu.org ↗ severe-fallout +0.00
Neutral
"Current Data Breaches Archive | Class Action U"
www.vulncheck.com ↗ severe-fallout +0.00
Neutral
"VulnCheck Advisories"
www.enforcementtracker.com ↗ severe-fallout +0.00
Neutral
"Fines Database — GDPR Enforcement Tracker"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.