Critical severity9.8CISA KEVNVD Advisory· Published Feb 2, 2021· Updated Jun 17, 2026
CVE-2020-25506
CVE-2020-25506
Description
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:dlink:dns-320_firmware:2.06b01:*:*:*:*:*:*:*
- D-Link/DNS-320description
Patches
Vulnerability mechanics
References
4- gist.github.com/WinMin/6f63fd1ae95977e0e2d49bd4b5f00675nvdExploitThird Party Advisory
- supportannouncement.us.dlink.com/announcement/publication.aspxnvdVendor Advisory
- www.dlink.com/en/security-bulletin/nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
1- RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning ExploitsTrend Micro Research · Oct 9, 2025