peter bassill · operator
$ cve CVE-2025-44084 JSON

CVE-2025-44084

9.8
CRITICAL · CVSS 3.1 · EPSS 20.1% (pctl 97)

Patch early

EPSS 20.1% — above the 10% action threshold.

Description

D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS20.08% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2025-05-20
Last modified2026-06-17

Affected (2)

VendorProduct
dlinkdi-8100
dlinkdi-8100g firmware

References

→ the Explorer  ·  watch your stack  ·  NVD