PT-2025-38478 · D Link · D-Link Dir-645

Lexpl0It

·

Published

2025-09-09

·

Updated

2025-10-03

·

CVE-2025-10689

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-645 version 105B01
Description A vulnerability was identified in the soapcgi main function of the /soap.cgi file. Manipulation of the service argument leads to command injection, allowing for remote attacks. The exploit is publicly available. This vulnerability affects products that are no longer supported by the maintainer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-12538
CVE-2025-10689

Affected Products

D-Link Dir-645