CVE-2025-44084

D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.
Configurations

No configuration.

History

21 May 2025, 20:24

Type Values Removed Values Added
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/piposy/IOTsec/blob/main/Dlink/DI8100/DI8100-A1-2.md - () https://github.com/piposy/IOTsec/blob/main/Dlink/DI8100/DI8100-A1-2.md -

20 May 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-20 17:15

Updated : 2025-05-21 20:24


NVD link : CVE-2025-44084

Mitre link : CVE-2025-44084

CVE.ORG link : CVE-2025-44084


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')