CVE-2020-15893 is a critical command injection vulnerability affecting D-Link DIR-816L routers running firmware versions 2.x before 1.10b04Beta02. An unauthenticated attacker can exploit this by injecting a payload into the Search Target (ST) field of an SSDP M-SEARCH discover packet, leveraging the default-enabled UPnP service on port 1900. With a CVSS score of 9.8 (CRITICAL), this vulnerability allows for complete compromise of confidentiality, integrity, and availability, requiring no user interaction or privileges. Exploit code is publicly available via a Metasploit module, and while not on CISA's KEV catalog, it has garnered significant community discussion and media coverage, indicating a high potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.06CPE matchmatch criteria | cpe:2.3:o:dlink:dir-816l_firmware:2.06:*:*:*:*:*:*:* | ||
2.06.b09CPE matchmatch criteria | cpe:2.3:o:dlink:dir-816l_firmware:2.06.b09:beta:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.