CVE-2025-25893

CVSS 3.1 Score 8 of 10 (high)

Details

Published Feb 18, 2025
Updated: Feb 19, 2025
CWE ID 78

Summary

CVE-2025-25893 is a newly discovered vulnerability affecting D-Link DSL-3782 v1.01 routers. This issue permits attackers to inject and execute arbitrary OS commands through the router's inIP, insPort, inePort, exsPort, exePort, and protocol parameters. A maliciously crafted packet can exploit this command injection vulnerability, potentially granting attackers significant control over the affected system. Successful exploitation could lead to unauthorized access, data theft, or even system compromise. Router users are strongly advised to apply the necessary patches or upgrades to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share