vulnerability

D-Link DNS-320: CVE-2020-25506: Improper Neutralization of Special Elements used in an OS Command

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Feb 2, 2021
Added
Aug 19, 2025
Modified
Aug 19, 2025

Description

D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.

Solution

d-link-dns-320-cve-2020-25506-no-fix
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.