A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cgibin of the component Simple Service Discovery Protocol. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
History

Mon, 18 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dir-860l
Dlink dir-860l Firmware
CPEs cpe:2.3:h:dlink:dir-860l:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-860l_firmware:2.04.b04:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dir-860l
Dlink dir-860l Firmware

Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dir-860l
Vendors & Products D-link
D-link dir-860l

Fri, 15 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Aug 2025 09:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cgibin of the component Simple Service Discovery Protocol. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Title D-Link DIR-860L Simple Service Discovery Protocol cgibin ssdpcgi_main os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-08-15T09:32:06.504Z

Updated: 2025-08-15T14:57:03.873Z

Reserved: 2025-08-14T07:15:30.188Z

Link: CVE-2025-9026

cve-icon Vulnrichment

Updated: 2025-08-15T14:56:59.541Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-15T10:15:27.000

Modified: 2025-08-18T15:10:41.840

Link: CVE-2025-9026

cve-icon Redhat

No data.