CVE-2020-9377
dlink dir-610 firmware
Published 9 Jul 2020 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 25 Mar 2022, with a remediation deadline of 15 Apr 2022 for US federal agencies.
Required action: The impacted product is end-of-life and should be disconnected if still in use.
Description
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
References
- gist.github.com/GouveaHeitor/131557f9de7d571f118f59805df852dc · Broken Link, Exploit, Patch
- supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10182 · Exploit, Vendor Advisory
- www.dlink.com.br/produto/dir-610/ · Product, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9377 · US Government Resource