Unauthenticated Remote Code Execution Vulnerability in D-Link Router DIR-868L
CVE-2025-63932
7.3HIGH
What is CVE-2025-63932?
The D-Link Router DIR-868L A1 FW106KRb01.bin is susceptible to an unauthenticated remote code execution vulnerability in its cgibin binary. The HNAP service, which is part of the router's functionality, fails to properly filter the HTTP SOAPAction header field, allowing unauthenticated remote attackers to execute arbitrary shell commands on the affected device. This vulnerability poses a significant risk to network security, enabling potential exploitation by malicious actors.