OS Command Injection Vulnerability in D-Link DIR-818LW
CVE-2025-7553

5.1MEDIUM

Key Information:

Vendor

D-link

Status
Vendor
CVE Published:
14 July 2025

What is CVE-2025-7553?

A security flaw related to OS command injection has been identified in the D-Link DIR-818LW, specifically affecting versions up to 20191215. This vulnerability resides in the System Time Page component where improper handling of the NTP Server argument allows an attacker to execute arbitrary commands on the device. This can be exploited remotely, posing significant risks to users. It is important to note that this vulnerability affects products that are no longer actively supported by D-Link, making them susceptible to exploitation if not addressed.

Affected Version(s)

DIR-818LW 20191215

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

.