VendorsD-Linkdch-m225any version
Vulnerabilities

D-Link DCH-M225 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-6841
D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.php userName parameter.
Published 2020-02-21 · Modified
10.0EPSS 0.028
CVE-2020-6842
D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media renderer name.
Published 2020-02-21 · Modified
9.0EPSS 0.023