OS Command Injection Vulnerability in D-Link DIR-818LW
CVE-2025-7553

4.7MEDIUM

Key Information:

Vendor

D-Link

Status
Vendor
CVE Published:
14 July 2025

What is CVE-2025-7553?

A security flaw related to OS command injection has been identified in the D-Link DIR-818LW, specifically affecting versions up to 20191215. This vulnerability resides in the System Time Page component where improper handling of the NTP Server argument allows an attacker to execute arbitrary commands on the device. This can be exploited remotely, posing significant risks to users. It is important to note that this vulnerability affects products that are no longer actively supported by D-Link, making them susceptible to exploitation if not addressed.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-7553 : OS Command Injection Vulnerability in D-Link DIR-818LW