Command Injection Vulnerability in D-Link DIR-882 Router Firmware
CVE-2025-60697

7.3HIGH

Key Information:

Vendor

D-Link

Vendor
CVE Published:
13 November 2025

What is CVE-2025-60697?

A command injection vulnerability exists in the D-Link DIR-882 Router firmware that allows attackers to execute arbitrary commands on the device. This issue is caused by the improper handling of user-supplied Dynamic DNS parameters, which are stored in NVRAM. When these values are later used without adequate sanitization, an unauthenticated remote attacker can exploit this flaw by sending specially crafted HTTP requests to the router's web interface. This vulnerability poses a significant risk as it enables the execution of malicious commands, potentially compromising the device.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.