Command Injection Vulnerability in D-Link DSL-7740C Router
CVE-2025-29519

5.3MEDIUM

Key Information:

Vendor

D-Link

Vendor
CVE Published:
25 August 2025

What is CVE-2025-29519?

The D-Link DSL-7740C router has a command injection vulnerability that arises from improper handling of the EXE parameter. Attackers can exploit this flaw by sending a specially crafted GET request that allows them to execute arbitrary commands on the device. This vulnerability compromises network integrity, potentially leading to unauthorized access and control of the affected router. It is essential for users to update their firmware to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.