Command Injection Vulnerability in D-Link DIR-852 Web Management Interface
CVE-2025-10628
Key Information:
Badges
What is CVE-2025-10628?
A command injection vulnerability exists in the web management interface of D-Link DIR-852 devices, specifically affecting the hedwig.cgi file. This vulnerability allows remote attackers to execute arbitrary commands on the affected system. The issue arises from inadequate input validation, enabling malicious actors to manipulate requests and inject harmful commands. This flaw predominantly affects outdated products that no longer receive support from D-Link, increasing the risks associated with continued usage of these devices.
Affected Version(s)
DIR-852 1.00CN B09
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved