PT-2026-27323 · D Link · Dir-825
1935648903
+1
·
Publicado
2026-03-24
·
Atualizado
2026-03-24
·
CVE-2026-4627
CVSS v2.0
8.3
Alta
| Vetor | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-825 versions 1.0.5 and 4.5.1
D-Link DIR-825R versions 1.0.5 and 4.5.1
Description
A flaw exists in the NTP Service component of D-Link DIR-825 and DIR-825R. The issue is located within the
handler update system time function of the libdeuteron modules.so file. Successful manipulation of this function can lead to operating system command injection. The attack can be initiated remotely. It is important to note that this issue only impacts products that are no longer receiving support from the maintainer.Recommendations
D-Link DIR-825 version 1.0.5: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
D-Link DIR-825 version 4.5.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
D-Link DIR-825R version 1.0.5: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
D-Link DIR-825R version 4.5.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dir-825