PT-2025-7101 · D Link · D-Link Dir-853

CVE-2025-25743

·

Published

2025-02-07

·

Updated

2025-02-12

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: D-Link DIR-853 A1 version FW1.20B07
Description: A command injection issue was discovered in the SetVirtualServerSettings module. This allows for potential exploitation.
Recommendations: For D-Link DIR-853 A1 version FW1.20B07, consider disabling the SetVirtualServerSettings module until a patch is available. Restrict access to this module to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05390
CVE-2025-25743

Affected Products

D-Link Dir-853