OS Command Injection Vulnerability in D-Link Routers
CVE-2025-10441
Key Information:
Badges
What is CVE-2025-10441?
A notable vulnerability exists in the D-Link DI-8100G, DI-8200G, and DI-8003G routers, specifically within the jhttpd component's version_upgrade.asp file. Manipulation of the 'path' argument leads to OS command injection, allowing attackers to execute arbitrary commands on the affected system. This vulnerability can be exploited remotely, significantly raising its risk profile. Security updates and best practices should be employed to mitigate potential attacks exploiting this weakness. Detailed references and patch information can be found on D-Link's official site and security advisories.
Affected Version(s)
DI-8003G 17.12.20A1
DI-8003G 19.12.10A1
DI-8100G 17.12.20A1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved