← Back to browse · API

CVE-2020-25367

Severity
CRITICAL
CVSS
9.8
EPSS
0.08651
Risk score
42.23
CISA KEV
No
PoC
No
Published
2021-11-04
Modified
2026-07-09
First seen
2026-08-05
Aliases
EUVD-2020-18054, GHSA-896V-RQ93-X779
Products
dlink:dir-823g, dlink:dir-823g_firmware, n/a:n/a n/a
Sources
nvd CVE-2020-25367
euvd EUVD-2020-18054

Description

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.

References