CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. Its EPSS score suggests a 20.9% probability of exploitation in the next 30 days.
CVE
CVE-2020-15893
Severity
CRITICAL
CVSS
9.8
EPSS
20.86%
Original NVD Description
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.
Related CVEs
Other vulnerabilities affecting the same vendor(s)