PatchSiren

PatchSiren cyber security CVE debrief

CVE-2020-9377 D-Link CVE debrief

CVE-2020-9377 is a D-Link DIR-610 device remote command execution issue that CISA lists in its Known Exploited Vulnerabilities catalog. The CISA entry identifies the impacted product as end-of-life and states that it should be disconnected if still in use. For defenders, this is an urgent exposure-management item rather than a routine patch cycle update.

Vendor
D-Link
Product
DIR-610 Devices
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2022-03-25
Original CVE updated
2022-03-25
Advisory published
2022-03-25
Advisory updated
2022-03-25

Who should care

Organizations that still have D-Link DIR-610 devices on the network, especially asset owners, network administrators, security teams, and incident responders responsible for end-of-life infrastructure.

Technical summary

The available official metadata identifies the vulnerability as remote command execution affecting D-Link DIR-610 devices. CISA’s KEV record marks it as a known exploited vulnerability and notes that the product is end-of-life. Because the device is no longer supported, CISA’s required action is to disconnect it if it remains in service.

Defensive priority

Urgent / highest priority. End-of-life devices listed in the KEV catalog should be treated as immediate removal or isolation candidates.

Recommended defensive actions

  • Inventory the environment for any D-Link DIR-610 devices.
  • If any are found, disconnect them from the network per CISA guidance.
  • Replace the device with a supported product rather than relying on patching.
  • Review whether the device had any exposed management or routing functions and rotate or retire any dependent credentials and configurations.
  • Document remediation and confirm the device is no longer reachable on production or internet-facing networks.

Evidence notes

Source item metadata identifies vendor D-Link, product DIR-610 Devices, and vulnerability name as remote command execution. The CISA KEV record includes dateAdded 2022-03-25, dueDate 2022-04-15, knownRansomwareCampaignUse as Unknown, and the required action: "The impacted product is end-of-life and should be disconnected if still in use."

Sources and references

Verified primary and authoritative sources

  • CVE-2020-9377 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2020-9377

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2020-9377 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2020-9377

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.