Command Injection Vulnerability in D-Link DIR-878A1 Router Firmware
CVE-2025-60673
6.5MEDIUM
What is CVE-2025-60673?
A command injection vulnerability exists in the D-Link DIR-878A1 router firmware. This flaw is triggered through the 'SetDMZSettings' function, where the 'IPAddress' parameter is improperly handled. When an attacker sends a malicious HTTP request, it exploits this weakness to execute arbitrary commands on the device. The vulnerability allows for remote exploitation without requiring authentication, compromising the device's security and integrity.