PT-2025-35426 · D Link · Jhttpd+1

Physicszq

·

Published

2025-08-30

·

Updated

2025-09-04

·

CVE-2025-9745

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DI-500WF version 14.04.10A1T
Description A security issue has been identified in D-Link DI-500WF. The vulnerability resides in an unknown function within the /version upgrade.asp file of the jhttpd component. Manipulation of the path argument can lead to os command injection, allowing for remote exploitation. The exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-11435
CVE-2025-9745

Affected Products

Di-500Wf
Jhttpd