critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-25506 Scanner

CVE-2020-25506 scanner - Remote Code Execution (RCE) vulnerability in D-Link DNS-320 FW

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-25506
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

The D-Link DNS-320 FW is a network-attached storage device that is used to store and share files and media content across a network. It is a reliable and versatile product that is designed to meet the needs of home and small office users. With its advanced capabilities, it offers a simple and efficient way of ensuring that data is always accessible and secure.

However, the D-Link DNS-320 FW product has recently been found to be affected by a critical vulnerability identified as CVE-2020-25506. This vulnerability allows attackers to execute arbitrary code on the system by exploiting the command injection flaw in the system_mgr.cgi component. This can be done remotely, by sending malicious HTTP requests directly to the device.

If this vulnerability is successfully exploited, it can lead to the complete takeover of the network-attached storage device. This can have severe implications where sensitive data and confidential files are involved. Attackers can use this vulnerability to gain unauthorized access to the device and steal sensitive information or cause data loss.

Overall, it's essential to be aware of the potential vulnerabilities within digital assets such as the D-Link DNS-320 FW. With the pro features of the s4e.io platform, users can easily and quickly learn about any such vulnerabilities with their digital assets. This includes regularly keeping up to date with the latest firmware updates and taking the necessary precautions to protect their devices from potential attackers. By taking these steps, users can ensure that their data remains secure and accessible only to authorized parties.

 

REFERENCES

Solution Advice

To safeguard against this vulnerability, users are advised to implement the following precautions:

  • Apply the latest firmware updates that address the vulnerability.
  • Disable remote access to the device if it is not required.
  • Configure the device to only accept secure HTTPS connections.
  • Limit the number of users with administrative privileges.
  • Enable network segmentation to isolate the device from external threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.