← Back to CVE List

CVE-2020-25757

Published: 2020-12-15T20:15Z
Last Modified: 2024-11-21T05:18Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with firmware 3.14 and 3.17. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt