PT-2025-19931 · D Link · D-Link Dir-880L

Babyshark

+1

·

Published

2025-05-06

·

Updated

2025-05-13

·

CVE-2025-4341

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-880L versions up to 104WWb01
Description A critical vulnerability was found in the Request Header Handler component, specifically affecting the function sub 16570 of the file /htdocs/ssdpcgi. The manipulation of the argument HTTP ST/REMOTE ADDR/REMOTE PORT/SERVER ID leads to command injection. This issue can be exploited remotely. The exploit has been publicly disclosed, making it potentially usable. This vulnerability only affects products that are no longer supported by the maintainer.
Recommendations For D-Link DIR-880L versions up to 104WWb01, as a temporary workaround, consider restricting access to the /htdocs/ssdpcgi file to minimize the risk of exploitation. Additionally, avoid using the HTTP ST/REMOTE ADDR/REMOTE PORT/SERVER ID argument in the affected component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-05479
CVE-2025-4341

Affected Products

D-Link Dir-880L