EXPOSURES › CVE-2020-25506
CVE-2020-25506
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link DNS-320 devices suffer from an unpatched command injection vulnerability enabling remote code execution.
The DNS-320 device's sytem_mgr.cgi component allows remote code execution via command injection, a flaw actively exploited in the wild. D-Link's history of unpatched RCE vulnerabilities across its product line demonstrates a pattern of poor vulnerability management that poses significant risk to CMMC environments requiring strict control over networked hardware.
Shame score — The vulnerability is actively exploited in the wild and D-Link has a documented history of leaving critical RCE flaws unpatched across its product line.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.