Command Injection Vulnerability in D-Link DIR-823G Router Firmware
CVE-2025-60671

5.4MEDIUM

Key Information:

Vendor

D-Link

Vendor
CVE Published:
13 November 2025

What is CVE-2025-60671?

A command injection vulnerability allows attackers with write access to the /var/system/linux_vlan_reinit file in the D-Link DIR-823G router firmware to execute arbitrary commands on the device. This issue arises from insufficient validation of the content read from the aforementioned file, allowing the processed input to be formatted and executed without proper checks. Users are urged to apply security updates promptly to mitigate the risks associated with unauthorized command execution.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.