CVE-2025-22968
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 15, 2025
Updated: Jan 16, 2025
CWE ID 94
Summary
CVE-2025-22968 is a vulnerability affecting D-Link DWR-M972V 1.05SSG devices. This issue permits a remote attacker to execute arbitrary code on the device by exploiting a weakness in its SSH functionality. The root account, which typically comes with unrestricted access, is the entry point for this exploit, posing a significant security risk. This vulnerability can potentially lead to unauthorized system takeover and data theft. It is crucial that affected device users apply the necessary patches to mitigate this risk promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.