Unauthenticated Command Injection in D-Link DSP-W110A1 Firmware
CVE-2025-34125
Key Information:
- Vendor
D-link
- Status
- Vendor
- CVE Published:
- 16 July 2025
Badges
What is CVE-2025-34125?
An unauthenticated command injection vulnerability exists within the cookie handling process of the D-Link DSP-W110A1 firmware. This vulnerability allows attackers to send specially crafted cookie values to the lighttpd web server, which can lead to the execution of arbitrary commands on the underlying Linux operating system. By exploiting this vulnerability, attackers could potentially gain full control over the system, thus posing a significant risk to the security and integrity of the device and its associated network.
Affected Version(s)
DSP-W110A1 1.05B01
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved