Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-25506 PoC — D-Link DNS-320 命令注入漏洞

Source
Associated Vulnerability
Title:D-Link DNS-320 命令注入漏洞 (CVE-2020-25506)
Description:D-Link DNS-320是中国台湾友讯(D-Link)公司的一款NAS(网络附属存储)设备。 D-Link DNS-320 FW v2.06B01 Revision 存在命令注入漏洞,该漏洞源于mgr.cgi组件中的命令注入影响,可能导致远程任意执行代码。
Description
D-Link DNS-320 FW v2.06B01 Revision Ax is susceptible to a command injection vulnerability in a system_mgr.cgi component. The component does not successfully sanitize the value of the HTTP parameters f_ntp_server, which in turn leads to arbitrary command execution.
File Snapshot

id: CVE-2020-25506 info: name: D-Link DNS-320 - Unauthenticated Remote Code Execution author: g ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.