Unauthenticated Command Injection Vulnerability in D-Link DIR-878A1 Router Firmware
CVE-2025-60672

6.5MEDIUM

Key Information:

Vendor

D-Link

Vendor
CVE Published:
13 November 2025

What is CVE-2025-60672?

An unauthenticated command injection vulnerability has been identified in the D-Link DIR-878A1 router firmware, specifically in the 'SetDynamicDNSSettings' function. This vulnerability arises due to improper handling of the 'ServerAddress' and 'Hostname' parameters in the prog.cgi component, where values are improperly stored in NVRAM. Consequently, an attacker can exploit this flaw remotely by sending specially crafted HTTP requests, leading to arbitrary command execution on the vulnerable device without requiring authentication. This poses significant risks to device integrity and network security.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.