CVE-2020-25759: D-Link Dsr-1000 Firmware

High severity, CVSS 8.8. EPSS: 2.3% chance of exploitation in the next 30 days.

An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.

Affected products

  • D-Link Dsr-1000 Firmware: up to and including 3.17
  • D-Link Dsr-1000ac Firmware: up to and including 3.17
  • D-Link Dsr-1000n Firmware: up to and including 3.17
  • D-Link Dsr-150 Firmware: up to and including 3.17
  • D-Link Dsr-150n Firmware: up to and including 3.17
  • D-Link Dsr-250 Firmware: up to and including 3.17
  • D-Link Dsr-250n Firmware: up to and including 3.17
  • D-Link Dsr-500 Firmware: up to and including 3.17
  • D-Link Dsr-500ac Firmware: up to and including 3.17
  • D-Link Dsr-500n Firmware: any version

Published 2020-12-15. Last modified 2026-06-17.