PT-2025-39210 · D Link · D-Link C1

CVE-2025-57636

·

Published

2025-09-23

·

Updated

2025-09-26

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions D-Link C1 versions prior to 2020-02-21
Description A command injection issue exists in the jhttpd component of the D-Link C1. The sub 47F028 function is susceptible to command injection through the time HTTP parameter. This allows for potential unauthorized system access.
Recommendations Update to a version later than 2020-02-21. As a temporary workaround, restrict access to the time parameter in the affected API endpoint.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12531
CVE-2025-57636

Affected Products

D-Link C1