CVE-2025-44084
9.8
CRITICAL · CVSS 3.1 · EPSS 20.1% (pctl 97)
Patch early
EPSS 20.1% — above the 10% action threshold.
Description
D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 20.08% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2025-05-20 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| dlink | di-8100 |
| dlink | di-8100g firmware |
References
→ the Explorer · watch your stack · NVD