ZeroHour

CVE-2020-9377

KEV PoC ×2moderate

OS Command Injection RCE in D-Link DIR-610 Routers

CISA: D-Link DIR-610 Devices Remote Command Execution

CVSS 3.1
8.8 high
EPSS
21%p97
Published
()
KEV added
AI analysis

D-Link DIR-610 routers contain an OS command injection flaw (CWE-78) in command.php, where the cmd parameter is passed to the underlying operating system without adequate sanitization, allowing remote attackers to execute arbitrary commands on the device. The flaw is triggered by sending a crafted HTTP request to command.php with a malicious cmd parameter. Successful exploitation yields remote command execution on the router, which an attacker can leverage for device takeover or as a foothold into the network behind it. Only D-Link DIR-610 devices, a consumer router line that has reached end-of-life, are affected. The vulnerability is listed in the CISA KEV catalog (added 2022-03-25), indicating it is being exploited in the wild, and its high EPSS percentile (97th, 21.3% probability of exploitation in 30 days) reinforces elevated risk despite no known public proof-of-concept.

What to do: Disconnect or replace DIR-610 routers, which are end-of-life, consistent with CISA's required action; no fixed firmware version is specified in the available data. If replacement is not immediate, block WAN access to the router web interface (including command.php) and review logs for suspicious requests carrying a cmd parameter that could indicate compromise.

Affected
D-Link DIR-610 devices
Estimated exposure
moderateLikely a few thousand internet-exposed units (estimate; no public scan count specific to DIR-610) — The DIR-610 is a discontinued entry-level consumer router; legacy D-Link models generally account for thousands of internet-exposed devices in public scans, and this older model is a small share of that footprint, so only a few thousand…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CISA Known Exploited Vulnerability
Affected
D-Link DIR-610 Devices
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dir-610 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news