Access Control Flaw in D-Link DSL-7740C Router by D-Link
CVE-2025-29515

9.8CRITICAL

Key Information:

Vendor

D-Link

Vendor
CVE Published:
25 August 2025

What is CVE-2025-29515?

An access control vulnerability in the DELT_file.xgi endpoint of the D-Link DSL-7740C router permits attackers to alter arbitrary settings in the device's XML database. This flaw allows unauthorized users to modify critical configurations, including the administrator’s password, thereby compromising the security of the device and the network it serves.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-29515 : Access Control Flaw in D-Link DSL-7740C Router by D-Link