Command Injection Vulnerability in D-Link Unified Services Router
CVE-2020-25759
8.8HIGH
Summary
A vulnerability exists on D-Link DSR-250 3.17 devices that can be exploited through the Unified Services Router web interface. An authenticated attacker may leverage a lack of input validation when processing multipart HTTP POST requests, allowing for the execution of arbitrary commands on the device. This flaw can potentially compromise the device's integrity and security, highlighting the need for robust validation mechanisms in network equipment.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved