CVE-2020-25506: D-Link DNS-320 Device Command Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 100% chance of exploitation in the next 30 days.
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
Affected products
- D-Link DNS-320 Firmware: version 2.06b01 only
Published 2021-02-02. Last modified 2026-06-17.