CISA Known Exploited Vulnerability

CVE-2020-9377

D-Link · DIR-610 Devices

D-Link DIR-610 Devices Remote Command Execution

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Unknown

CISA description

D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.

Required action

The impacted product is end-of-life and should be disconnected if still in use.