PT-2025-35092 · D Link · D-Link Dir-868L
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-868L B1 router firmware version FW2.05WWB02
Description
The
fileaccess.cgi component contains an unauthenticated OS command injection flaw. The endpoint '/dws/api/UploadFile' accepts a pre api arg parameter that is passed directly to system-level shell execution functions without proper sanitization or authentication. This allows remote attackers to execute arbitrary commands with root privileges using specially crafted HTTP requests.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
pre api arg parameter in the '/dws/api/UploadFile' endpoint to minimize the risk of exploitation.Exploit
OS Command Injection
Missing Authentication
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-868L