Remote Code Execution Vulnerability in D-Link DCH-M225 Devices
CVE-2020-6841
9.8CRITICAL
Summary
The D-Link DCH-M225 device, running version 1.05b01 and earlier, is susceptible to a vulnerability that enables remote attackers to execute arbitrary operating system commands. This occurs through the manipulation of shell metacharacters within the 'userName' parameter of the spotifyConnect.php script. When exploited, this security flaw could potentially allow unauthorized individuals to gain control over the system, posing significant risks to the integrity of the device and the network it operates within.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved