D-Link DNS-320 FW v2.06B01 Revision Ax is susceptible to a command injection vulnerability in a system_mgr.cgi component. The component does not successfully sanitize the value of the HTTP parameters f_ntp_server, which in turn leads to arbitrary command execution.
View the template here CVE-2020-25506.yaml
References:
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10183