← Zuruck zu CVEs
CVE-2025-44084
CRITICAL9.8
Beschreibung
D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht5/20/2025
Zuletzt geandert5/30/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
dlink:di-8100dlink:di-8100g_firmware
Schwachen (CWE)
CWE-77
Referenzen
https://github.com/piposy/IOTsec/blob/main/Dlink/DI8100/DI8100-A1-2.md(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.