CVE-2025-25893

An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dsl-3782_firmware:1.01:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dsl-3782:-:*:*:*:*:*:*:*

History

02 May 2025, 15:46

Type Values Removed Values Added
CPE cpe:2.3:o:dlink:dsl-3782_firmware:1.01:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dsl-3782:-:*:*:*:*:*:*:*
First Time Dlink
Dlink dsl-3782
Dlink dsl-3782 Firmware
References () https://github.com/2664521593/mycve/blob/main/CJ_in_D-Link_DSL-3782_2_en.pdf - () https://github.com/2664521593/mycve/blob/main/CJ_in_D-Link_DSL-3782_2_en.pdf - Broken Link

18 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-18 22:15

Updated : 2025-05-02 15:46


NVD link : CVE-2025-25893

Mitre link : CVE-2025-25893


JSON object : View

Products Affected

dlink

  • dsl-3782
  • dsl-3782_firmware
CWE

No CWE.