CVE-2025-6896

A vulnerability classified as critical has been found in D-Link DI-7300G+ 19.12.25A1. Affected is an unknown function of the file wget_test.asp. The manipulation of the argument url leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

30 Jun 2025, 18:38

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad crítica en D-Link DI-7300G+ 19.12.25A1. Se ve afectada una función desconocida del archivo wget_test.asp. La manipulación del argumento url provoca la inyección de comandos del sistema operativo. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado .

30 Jun 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-30 07:15

Updated : 2025-06-30 18:38


NVD link : CVE-2025-6896

Mitre link : CVE-2025-6896

CVE.ORG link : CVE-2025-6896


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')