PT-2025-37463 · D Link+1 · D-Link Di-8200+3

Shiny

·

Published

2025-09-14

·

Updated

2025-09-15

·

CVE-2025-10440

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions D-Link DI-8100 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1 D-Link DI-8100G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1 D-Link DI-8200 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1 D-Link DI-8200G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1 D-Link DI-8003 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1 D-Link DI-8003G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1
Description A vulnerability exists in D-Link routers due to a command injection issue. The sub 4621DC function within the usb paswd.asp file of the jhttpd component is susceptible to exploitation. Manipulation of the hname argument can lead to operating system command injection. This attack can be initiated remotely.
Recommendations D-Link DI-8100 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability. D-Link DI-8100G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability. D-Link DI-8200 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability. D-Link DI-8200G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability. D-Link DI-8003 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability. D-Link DI-8003G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14835
CVE-2025-10440

Affected Products

D-Link Di-8003
D-Link Di-8100
D-Link Di-8200
Jhttpd