PT-2025-34935 · D Link · Dcs-825L

Shaunak Ganorkar

·

Published

2025-08-27

·

Updated

2025-08-28

·

CVE-2025-55582

CVSS v3.1
6.6
VectorAV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

D-Link DCS-825L firmware versions prior to 1.09.02

Description:

The D-Link DCS-825L firmware contains a flaw in the watchdog script `mydlink-watch-dog.sh`. This script blindly respawns binaries, including `dcp` and `signalc`, without verifying their integrity, authenticity, or permissions. An attacker with local filesystem access can replace these binaries with malicious payloads. The script then executes these binaries as root in a continuous loop, resulting in persistent privilege escalation and arbitrary code execution.

Recommendations:

Update to firmware version 1.09.02 or later.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-55582

Affected Products

Dcs-825L