Command Injection Vulnerability in D-Link DIR-878A1 Router Firmware
CVE-2025-60673

6.5MEDIUM

Key Information:

Vendor

D-Link

Vendor
CVE Published:
13 November 2025

What is CVE-2025-60673?

A command injection vulnerability exists in the D-Link DIR-878A1 router firmware. This flaw is triggered through the 'SetDMZSettings' function, where the 'IPAddress' parameter is improperly handled. When an attacker sends a malicious HTTP request, it exploits this weakness to execute arbitrary commands on the device. The vulnerability allows for remote exploitation without requiring authentication, compromising the device's security and integrity.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-60673 : Command Injection Vulnerability in D-Link DIR-878A1 Router Firmware