CISA Known Exploited Vulnerability

CVE-2020-25506

D-Link · DNS-320 Device

D-Link DNS-320 Device Command Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Unknown

CISA description

D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.

Required action

Apply updates per vendor instructions.