CVE-2020-18568: D-Link Dsr-1000n Firmware

Critical severity, CVSS 9.8. EPSS: 14.6% chance of exploitation in the next 30 days.

The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.

Affected products

  • D-Link Dsr-1000n Firmware: version 2.11b201 only
  • D-Link Dsr-250 Firmware: version 3.14 only

Published 2021-02-02. Last modified 2026-06-17.