PT-2025-35092 · D Link · D-Link Dir-868L

·

CVE-2025-55583

·

Published

2025-08-21

·

Updated

2026-08-17

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-868L B1 router firmware version FW2.05WWB02
Description The fileaccess.cgi component contains an unauthenticated OS command injection flaw. The endpoint '/dws/api/UploadFile' accepts a pre api arg parameter that is passed directly to system-level shell execution functions without proper sanitization or authentication. This allows remote attackers to execute arbitrary commands with root privileges using specially crafted HTTP requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the pre api arg parameter in the '/dws/api/UploadFile' endpoint to minimize the risk of exploitation.

Exploit

OS Command Injection

Missing Authentication

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12546
CVE-2025-55583

Affected Products

D-Link Dir-868L