Command Injection Vulnerability in D-Link DIR-882 Router Firmware
CVE-2025-60698
What is CVE-2025-60698?
A command injection vulnerability has been identified in the firmware of the D-Link DIR-882 Router. The issue arises within the prog.cgi and rc binaries, specifically in the sub_432F60 function where user-provided values for SetSysLogSettings/IPAddress are stored in NVRAM. These values are later accessed and concatenated into a shell command in the sub_448DCC function, executed unsanitized through twsystem(). This flaw allows an unauthenticated remote attacker to exploit the device via crafted HTTP requests to the router's web interface, enabling command execution with potential malicious consequences.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved