CVE detail
CVE-2020-26582 — CVE-2020-26582
Published 2020-10-06 · Modified 2026-06-17 · Vendor dlink · Product dap-1360u_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0479
EPSS probability
exploitation probability, 30d
91.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the IP JSON value for ping (aka res_config_action=3&res_config_id=18).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References