Vulnerabilities (CVE)

Filtered by vendor Dlink Subscribe
Filtered by product Dch-m225 Firmware
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-6841 1 Dlink 2 Dch-m225, Dch-m225 Firmware 2023-12-10 10.0 HIGH 9.8 CRITICAL
D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.php userName parameter.
CVE-2020-6842 1 Dlink 2 Dch-m225, Dch-m225 Firmware 2023-12-10 9.0 HIGH 7.2 HIGH
D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media renderer name.