cbcvebase.
CVE-2020-13782
published 2020-06-03

CVE-2020-13782: D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
27.06%
97.8th percentile
D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

Affected

1 ranges
VendorProductVersion rangeFixed in
dlinkdir-865l_firmware

Detection & IOCsextracted from sources · hover to see the quote

url_ajax_explorer.sgi?action=
snort
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Possible D-Link Command Injection Attempt Inbound (CVE-2020-13782)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"_ajax_explorer.sgi?action="; fast_pattern; content:"&path="; distance:0; content:"&where="; distance:0; content:"&en=|3b|"; distance:0; reference:url,unit42.paloaltonetworks.com/6-new-d-link-vulnerabilities-found-on-home-routers/; reference:cve,2020-13782; classtype:attempted-admin; sid:2030335; rev:1; metadata:attack_target Networking_Equipment, created_at 2020_06_15, cve CVE_2020_13782, deployment Perimeter, deployment Internal, performance_impact Low, confidence Low, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_06_15, mitre_tactic_id TA0008, mitre_tactic_name Lateral_Movement, mitre_technique_id T1210, mitre_technique_name Exploitation_Of_Remote_Services;)
bytes
|3b|
  • Exploit requests target the CGI endpoint `_ajax_explorer.sgi` via HTTP GET with query parameters `action=`, `&path=`, `&where=`, and `&en=` containing a URL-encoded semicolon (`|3b|`) used to inject shell commands.
  • Traffic direction is inbound to the home/internal network (`to_server`), targeting Networking Equipment — monitor perimeter and internal HTTP traffic for this URI pattern.
  • MITRE ATT&CK mapping: Lateral Movement (TA0008) / Exploitation of Remote Services (T1210) — treat detections as potential lateral movement pivoting through the router.
  • ·The Snort/Suricata rule carries `confidence Low` metadata — expect potential false positives; tune to specific internal D-Link DIR-865L assets where possible.
  • ·Rule is designed for both Perimeter and Internal deployment contexts; ensure it is applied at both network boundaries for full coverage.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.