PT-2025-36463 · D Link · D-Link Dir-852

Ic0Rner

·

Published

2025-09-08

·

Updated

2025-09-08

·

CVE-2025-10093

CVSS v3.1
5.3
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

D-Link DIR-852 versions up to 1.00CN B09

Description:

A vulnerability exists in D-Link DIR-852 that allows for information disclosure. The vulnerability is located in the `phpcgi main` function of the `/getcfg.php` file within the Device Configuration Handler component. This manipulation can be performed remotely. The exploit is publicly available. This vulnerability affects products that are no longer supported by the maintainer.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-10093

Affected Products

D-Link Dir-852