Command Injection Vulnerability in D-Link DAP-2610 Web Interface
CVE-2025-51457
8.8HIGH
What is CVE-2025-51457?
The D-Link DAP-2610 features a significant command injection vulnerability within its web interface, specifically at the /index.xgi endpoint. This flaw allows attackers with authenticated access to manipulate certain parameters, leading to the execution of arbitrary system commands. This poses a serious security risk, as it enables malicious entities to compromise the integrity of affected devices. Users are advised to implement security best practices, including updating to the latest firmware, to mitigate the risk associated with this vulnerability.