CVE-2020-6842

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
21/02/2020
Last modified:
26/04/2023

Description

D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media renderer name.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dch-m225_firmware:*:*:*:*:*:*:*:* 1.05b01 (including)
cpe:2.3:h:dlink:dch-m225:-:*:*:*:*:*:*:*