critical Known exploitedREV. 01

CVE-2020-25506D-Link DNS-320 Command Injection — Unauthenticated Device Takeover

A command injection flaw in the web management interface of D-Link's network storage appliance (DNS-320) lets an attacker who can reach the device over the network run arbitrary system commands on it, with no credentials required.

YOUR NEXT MOVE

Apply D-Link's firmware update for the DNS-320, or take the device off the network until you can.

Read the risk

THE VITAL STATS
CVSS score
9.8/ 10
CVSS v3.1
EPSS probability
100%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Yes — CISA KEV
CVE published
2021-02-02
Added to KEV
2021-11-03
Exploit published
Yes
Confidence
high
Kill chain
initial access
MITRE ATT&CK
T1190, T1059
Severity
critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attacker needsNetwork access to the device's web management interface

Behind the card

4 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
cvss, references, exploitation.attack_complexitynvd.nist.gov2026-08-07claude-codehigh
exploitation.known_exploited, remediation.patch_availablecisa.gov2026-08-07claude-codehigh
epssapi.first.org2026-08-07claude-codehigh
title, summary, recommended_action, severity, kill_chain, mitre_attack, exploitation.prerequisites, exploitation.exploit_available, tagsnvd.nist.gov2026-08-07claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2020-25506 · CRDS 0.1 · Issued 2026-08-07