peter bassill · operator
$ cve CVE-2014-125117 JSON

CVE-2014-125117

9.8
CRITICAL · CVSS 3.1 · EPSS 7.2% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploited via a specially crafted HTTP POST request to the /common/info.cgi endpoint. This flaw enables an unauthenticated attacker to achieve remote code execution with system-level privileges.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.22% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2025-07-25
Last modified2026-06-17

Affected (2)

VendorProduct
dlinkdsp-w215
dlinkdsp-w215 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD