CVE-2020-9377

D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • Published Jul 9, 2020
  • CVSS 8.8 high
  • 21.3% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • Public exploit code is available
  • No fix is known yet

CVE-2020-9377 at the National Vulnerability Database