Skip to content
COOEY

EXPOSURES › CVE-2020-9377

CVE-2020-9377

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-9377 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

D-Link DIR-610 devices allow remote code execution via an unpatched vulnerability in command.php.

An unpatched remote code execution flaw in D-Link DIR-610 devices allows attackers to execute arbitrary commands remotely. DIB organizations must ensure all network hardware is patched and monitored, as unpatched RCE vulnerabilities are frequently exploited in the wild and can lead to full device compromise.

Shame score — D-Link shipped devices with a known, unpatched RCE vulnerability that was actively exploited in the wild, demonstrating negligence in patch management and supply chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.