peter bassill · operator
$ cve CVE-2018-25115 JSON

CVE-2018-25115

9.8
CRITICAL · CVSS 3.1 · EPSS 10.4% (pctl 96)

Patch early

EPSS 10.4% — above the 10% action threshold.

Description

Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication. The flaw stems from improper input handling in the EVENT=CHECKFW parameter, which is passed directly to the system shell without sanitization. A crafted HTTP POST request can inject commands that are executed with root privileges, resulting in full device compromise. These router models are no longer supported at the time of assignment and affected version ranges may vary. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-08-21 UTC.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.43% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2025-08-27
Last modified2026-06-17

Affected (14)

VendorProduct
dlinkdir-110
dlinkdir-110 firmware
dlinkdir-412
dlinkdir-412 firmware
dlinkdir-600
dlinkdir-600 firmware
dlinkdir-610
dlinkdir-610 firmware
dlinkdir-615
dlinkdir-615 firmware
dlinkdir-645
dlinkdir-645 firmware
dlinkdir-815
dlinkdir-815 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD