Unauthenticated Command Injection Vulnerability in D-Link DIR-878A1 Router Firmware
CVE-2025-60672
6.5MEDIUM
What is CVE-2025-60672?
An unauthenticated command injection vulnerability has been identified in the D-Link DIR-878A1 router firmware, specifically in the 'SetDynamicDNSSettings' function. This vulnerability arises due to improper handling of the 'ServerAddress' and 'Hostname' parameters in the prog.cgi component, where values are improperly stored in NVRAM. Consequently, an attacker can exploit this flaw remotely by sending specially crafted HTTP requests, leading to arbitrary command execution on the vulnerable device without requiring authentication. This poses significant risks to device integrity and network security.