EXPOSURES › CVE-2020-9377
CVE-2020-9377
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link DIR-610 devices allow remote code execution via an unpatched vulnerability in command.php.
An unpatched remote code execution flaw in D-Link DIR-610 devices allows attackers to execute arbitrary commands remotely. DIB organizations must ensure all network hardware is patched and monitored, as unpatched RCE vulnerabilities are frequently exploited in the wild and can lead to full device compromise.
Shame score — D-Link shipped devices with a known, unpatched RCE vulnerability that was actively exploited in the wild, demonstrating negligence in patch management and supply chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.