MEDIUM🇵🇱 Wersja polska

CVE-2025-9026

CVSS 5.5v4.0pub. 2025-08-15upd. 2026-04-29

A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cgibin of the component Simple Service Discovery Protocol. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Dlink Dir 860l

    HW
    Dlink
    all versions
  • Dlink Dir 860l Firmware

    OS
    Dlink
    2.04.b04
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2018-6530CRITICAL9.8⚠ KEVPL ✓same product

D-Link DIR-860L/865L/868L/880L — command injection przez soap.cgi

CVE-2024-42812CRITICAL9.8PL ✓same product

Buffer overflow w D-Link DIR-860L v2.03 — brak weryfikacji długości pola SID

CVE-2024-41611CRITICAL9.8PL ✓same product

D-Link DIR-860L: hardcoded credentials w usłudze Telnet umożliwiają RCE

CVE-2018-19987CRITICAL9.8PL ✓same product

Command injection w D-Link DIR-822/860L/868L/880L/890L przez HNAP1

CVE-2018-20114CRITICAL9.8PL ✓same product

D-Link DIR-818LW / DIR-860L — nieuwierzytelniony RCE przez command injection w soap.cgi