PT-2025-36463 · D Link · D-Link Dir-852

Ic0Rner

·

Published

2025-08-31

·

Updated

2025-09-08

·

CVE-2025-10093

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: D-Link DIR-852 versions up to 1.00CN B09
Description: A vulnerability exists in D-Link DIR-852 that allows for information disclosure. The vulnerability is located in the phpcgi main function of the /getcfg.php file within the Device Configuration Handler component. This manipulation can be performed remotely. The exploit is publicly available. This vulnerability affects products that are no longer supported by the maintainer.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-13368
CVE-2025-10093

Affected Products

D-Link Dir-852