CVE-2020-13782
published 2020-06-03CVE-2020-13782: D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.
PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
27.06%
97.8th percentile
D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-865l_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url_ajax_explorer.sgi?action=
snort
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Possible D-Link Command Injection Attempt Inbound (CVE-2020-13782)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"_ajax_explorer.sgi?action="; fast_pattern; content:"&path="; distance:0; content:"&where="; distance:0; content:"&en=|3b|"; distance:0; reference:url,unit42.paloaltonetworks.com/6-new-d-link-vulnerabilities-found-on-home-routers/; reference:cve,2020-13782; classtype:attempted-admin; sid:2030335; rev:1; metadata:attack_target Networking_Equipment, created_at 2020_06_15, cve CVE_2020_13782, deployment Perimeter, deployment Internal, performance_impact Low, confidence Low, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_06_15, mitre_tactic_id TA0008, mitre_tactic_name Lateral_Movement, mitre_technique_id T1210, mitre_technique_name Exploitation_Of_Remote_Services;)
bytes
|3b|
- →Exploit requests target the CGI endpoint `_ajax_explorer.sgi` via HTTP GET with query parameters `action=`, `&path=`, `&where=`, and `&en=` containing a URL-encoded semicolon (`|3b|`) used to inject shell commands.
- →Traffic direction is inbound to the home/internal network (`to_server`), targeting Networking Equipment — monitor perimeter and internal HTTP traffic for this URI pattern.
- →MITRE ATT&CK mapping: Lateral Movement (TA0008) / Exploitation of Remote Services (T1210) — treat detections as potential lateral movement pivoting through the router.
- ·The Snort/Suricata rule carries `confidence Low` metadata — expect potential false positives; tune to specific internal D-Link DIR-865L assets where possible.
- ·Rule is designed for both Perimeter and Internal deployment contexts; ensure it is applied at both network boundaries for full coverage.
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT Possible D-Link Command Injection Attempt Inbound (CVE-2020-13782)
suricata·2020-06-15·CVSS 8.8
CVE-2020-13782 [HIGH] ET EXPLOIT Possible D-Link Command Injection Attempt Inbound (CVE-2020-13782)
ET EXPLOIT Possible D-Link Command Injection Attempt Inbound (CVE-2020-13782)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Possible D-Link Command Injection Attempt Inbound (CVE-2020-13782)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"_ajax_explorer.sgi?action="; fast_pattern; content:"&path="; distance:0; content:"&where="; distance:0; content:"&en=|3b|"; distance:0; reference:url,unit42.paloaltonetworks.com/6-new-d-link-vulnerabilities-found-on-home-routers/; reference:cve,2020-13782; classtype:attempted-admin; sid:2030335; rev:1; metadata:attack_target Networking_Equipment, created_at 2020_06_15, cve CVE_2020_13782, deployment Perimeter, deployment Internal, performance_impact Low, confidence Low, signature_severity Major, tag Description_G
No public exploits indexed.
Unit42
6 New Vulnerabilities Found on D-Link Home Routers
blogs_unit42·2020-06-12·CVSS 8.8
[HIGH] 6 New Vulnerabilities Found on D-Link Home Routers
Threat Research Center
Threat Research
Vulnerabilities
## 6 New Vulnerabilities Found on D-Link Home Routers
Gregory Basior
Published: June 12, 2020
Threat Research
Vulnerabilities
D-Link
IoT
Wireless routers
## Executive Summary
On February 28, 2020, Palo Alto Networks’ Unit 42 researchers discovered six new vulnerabilities in D-Link wireless cloud routers running their latest firmware.
The vulnerabilities were found in the DIR-865L model of D-Link routers, which is meant for home network use. The current trend towards working from home increases the likelihood of malicious attacks against home networks, which makes it even more imperative to keeping our networking devices updated.
It is possible that some of these vulnerabilities are also present in newer models of the
Unit42
6 New Vulnerabilities Found on D-Link Home Routers
blogs_unit42·2020-06-12·CVSS 8.8
[HIGH] 6 New Vulnerabilities Found on D-Link Home Routers
## Executive Summary
On February 28, 2020, Palo Alto Networks’ Unit 42 researchers discovered six new vulnerabilities in D-Link wireless cloud routers running their latest firmware.
The vulnerabilities were found in the DIR-865L model of D-Link routers, which is meant for home network use. The current trend towards working from home increases the likelihood of malicious attacks against home networks, which makes it even more imperative to keeping our networking devices updated.
It is possible that some of these vulnerabilities are also present in newer models of the router because they share a similar codebase. The following are the six vulnerabilities found:
- - CVE-2020-13782: Improper Neutralization of Special Elements Used in a Command (Command Injection)
- CVE-2020-13786: Cross-Si
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10174https://unit42.paloaltonetworks.com/6-new-d-link-vulnerabilities-found-on-home-routers/https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10174https://unit42.paloaltonetworks.com/6-new-d-link-vulnerabilities-found-on-home-routers/
2020-06-03
Published