OS Command Injection Vulnerability in D-Link Routers
CVE-2025-10440
Key Information:
Badges
What is CVE-2025-10440?
A vulnerability exists in the jhttpd component of several D-Link routers, allowing remote attackers to execute arbitrary OS commands via crafted requests to the usb_paswd.asp file. Specifically, the issue is rooted in the manipulation of the 'hname' argument within the sub_4621DC function, enabling potential exploitation. Given the public disclosure of this vulnerability, immediate action is advised to secure affected devices.
Affected Version(s)
DI-8003 16.07.26A1
DI-8003 17.12.20A1
DI-8003 19.12.10A1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved