CVE-2018-6211: D-Link Dir-620 Firmware
High severity, CVSS 7.2. EPSS: 5.8% chance of exploitation in the next 30 days.
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is possible as a result of incorrect processing of the res_buf parameter to index.cgi.
Affected products
- D-Link Dir-620 Firmware: version 1.0.3 only; version 1.0.37 only; version 1.3.1 only; version 1.3.3 only; version 1.3.7 only; version 1.4.0 only; …
Published 2018-06-20. Last modified 2026-06-17.