Command Injection Vulnerability in D-Link DIR-852 Router
CVE-2025-10629
Key Information:
Badges
What is CVE-2025-10629?
A command injection vulnerability has been identified in the D-Link DIR-852 router, specifically within the Simple Service Discovery Protocol Service's ssdpcgi_main function located in the component htodcs/cgibin. This issue arises from improper handling of the ST argument, enabling attackers to execute arbitrary commands remotely. Notably, this vulnerability affects versions of the product that are no longer supported by the vendor, increasing the risks associated with potential exploitation.
Affected Version(s)
DIR-852 1.00CN B09
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved