CVE-2020-9377
KEV PoC ×2moderateOS Command Injection RCE in D-Link DIR-610 Routers
CISA: D-Link DIR-610 Devices Remote Command Execution
D-Link DIR-610 routers contain an OS command injection flaw (CWE-78) in command.php, where the cmd parameter is passed to the underlying operating system without adequate sanitization, allowing remote attackers to execute arbitrary commands on the device. The flaw is triggered by sending a crafted HTTP request to command.php with a malicious cmd parameter. Successful exploitation yields remote command execution on the router, which an attacker can leverage for device takeover or as a foothold into the network behind it. Only D-Link DIR-610 devices, a consumer router line that has reached end-of-life, are affected. The vulnerability is listed in the CISA KEV catalog (added 2022-03-25), indicating it is being exploited in the wild, and its high EPSS percentile (97th, 21.3% probability of exploitation in 30 days) reinforces elevated risk despite no known public proof-of-concept.
What to do: Disconnect or replace DIR-610 routers, which are end-of-life, consistent with CISA's required action; no fixed firmware version is specified in the available data. If replacement is not immediate, block WAN access to the router web interface (including command.php) and review logs for suspicious requests carrying a cmd parameter that could indicate compromise.
| D-Link DIR-610 devices | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- Affected
- D-Link DIR-610 Devices
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dir-610 firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H