CVE-2025-1800
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Mar 1, 2025
Updated: Mar 5, 2025
CWE ID 77
CWE ID 74
Summary
CVE-2025-1800 is a critical vulnerability affecting D-Link DAR-7000 3.2. The issue lies in the get_ip_addr_details function of the HTTP POST Request Handler's sxh_vpnlic.php file. Manipulation of the ethname argument permits command injection, allowing remote attacks. The exploit is public, and unsupported D-Link products are vulnerable.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.