LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-9377: D-Link DIR-610 Devices Remote Command Execution

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
CVSS 8.8 · High⚠ Actively exploited (CISA KEV)
8.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-9377 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2020-9377 is a remote command execution flaw in D-Link DIR-610 devices. An attacker can abuse the cmd parameter on command.php to run commands on the device. Because these routers often sit at the network edge, successful abuse can give an outsider a foothold into the local network. The product is end-of-life; CISA advises disconnecting any still in use.

How it works

The weakness is CWE-78 (OS command injection). The device exposes a web interface endpoint, command.php, that accepts a cmd parameter. When that parameter is not properly sanitized, an unauthenticated or lightly authenticated remote attacker can supply crafted input that the device executes as operating-system commands. This is a classic injection pattern for embedded network gear: the application layer passes attacker-controlled data straight to a shell or system call. Exact request format, authentication requirements, and any preconditions must be confirmed against the vendor advisory; public detail beyond the CISA summary is limited.

Am I affected? How to find it in your systems

D-Link DIR-610 devices are consumer and small-office wireless routers. They typically appear on home networks, branch offices, or lab segments where older hardware has not been refreshed.

Confirm exact affected firmware revisions and any residual support status directly with the vendor advisory; do not assume a version is safe without that check.

How to remediate

The definitive action is removal. CISA states the impacted product is end-of-life and should be disconnected if still in use. Replace the DIR-610 with a currently supported router, migrate configuration, and decommission the old unit (factory-reset and physically retire it).

If you can't patch immediately

Because the device is end-of-life, “patch later” is not a viable long-term plan. Until you can disconnect and replace it, apply these compensating controls:

These steps only reduce exposure; they do not eliminate the underlying command-injection risk. Schedule replacement immediately.

If your data may have been exposed

Actively exploited vulnerabilities on edge devices can lead to network compromise and data theft even when ransomware use has not been documented for this CVE. If the DIR-610 was internet-facing or held credentials, treat adjacent systems as potentially at risk: rotate secrets, review authentication logs, and check for unauthorized accounts or persistence. You can run a free exposure scan of your email addresses against known breach data to see whether associated credentials have already appeared in public dumps, then force password changes and enable multi-factor authentication where missing.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · DIR-610 Devices
WeaknessCWE-78
CVSS base score8.8 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PublishedJul 9, 2020
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities