← Vulnerability feed

Vulnerability record · CVE-2020-10216 · published 7 March 2020

CVE-2020-10216: Dlink dir-825 firmware os command injection vulnerability

Dlink · Dir 825 Firmware

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a system_time.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.

8.8 CVSS 3.1 High EPSS 5.0% · top 8.0% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
5.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a system_time.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-10216 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16920D-Link router PingTest CGI command injection allows unauthenticated RCEMultiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sani…KEVEPSS 100%analysed9.8CVE-2024-57590Trendnet tew-632brp firmware command injection vulnerabilityTRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to…EPSS 1.1%9.8CVE-2022-47035Dlink dir-825 firmware classic buffer overflow vulnerabilityBuffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method…EPSS 1.2%9.8CVE-2021-46442D-Link DIR-825 webupg authentication bypass via autoupgrade.aspThe webupg binary in D-Link DIR-825 G1 firmware mishandles the autoupgrade.asp parameter, allowing authentication to be bypassed. An unauthenticated …EPSS 56%analysed9.8CVE-2019-11418Trendnet tew-632brp firmware memory buffer overflow vulnerabilityapply.cgi on the TRENDnet TEW-632BRP 1.010B32 router has a buffer overflow via long strings to the SOAPACTION:HNAP1 interface.EPSS 1.5%8.9CVE-2025-7206Dlink dir-825 firmware memory buffer overflow vulnerabilityA vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. This issue affects the function sub_410DDC of the file swit…EPSS 18%8.8CVE-2021-46441Dlink dir-825 firmware os command injection vulnerabilityIn the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary s…EPSS 33%8.8CVE-2020-10213Dlink dir-825 firmware os command injection vulnerabilityAn issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin …EPSS 5.0%

Source: NIST National Vulnerability Database (record CVE-2020-10216), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.