PT-2025-37463 · D Link+1 · D-Link Di-8200+3
Shiny
·
Published
2025-09-14
·
Updated
2025-09-15
·
CVE-2025-10440
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
D-Link DI-8100 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1
D-Link DI-8100G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1
D-Link DI-8200 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1
D-Link DI-8200G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1
D-Link DI-8003 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1
D-Link DI-8003G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1
Description
A vulnerability exists in D-Link routers due to a command injection issue. The
sub 4621DC function within the usb paswd.asp file of the jhttpd component is susceptible to exploitation. Manipulation of the hname argument can lead to operating system command injection. This attack can be initiated remotely.Recommendations
D-Link DI-8100 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
D-Link DI-8100G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
D-Link DI-8200 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
D-Link DI-8200G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
D-Link DI-8003 versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
D-Link DI-8003G versions 16.07.26A1, 17.12.20A1, and 19.12.10A1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Special Elements Injection
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Di-8003
D-Link Di-8100
D-Link Di-8200
Jhttpd