PT-2025-26997 · D Link · D-Link Dsl-2750U+1

Todor Donev

·

Published

2012-05-23

·

Updated

2025-06-29

·

CVE-2025-34048

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: D-Link DSL-2730U version IN 1.02 D-Link DSL-2750U version SEA 1.04 D-Link DSL-2750E version SEA 1.07
Description: A path traversal vulnerability exists in the web management interface of D-Link ADSL routers due to insufficient input validation on the getpage parameter within the "/cgi-bin/webproc" CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device.
Recommendations: For D-Link DSL-2730U version IN 1.02, consider disabling the /cgi-bin/webproc CGI script until a patch is available. For D-Link DSL-2750U version SEA 1.04, restrict access to the getpage parameter to minimize the risk of exploitation. For D-Link DSL-2750E version SEA 1.07, avoid using the getpage parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Path traversal

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-07926
CVE-2025-34048

Affected Products

D-Link Dsl-2730B
D-Link Dsl-2750U