Back

CRITICAL

D-Link Devices command.php Unauthenticated RCE

Published Aug 1, 2025

Description

An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper input handling in the unauthenticated command.php endpoint. By sending specially crafted POST requests, a remote attacker can execute arbitrary shell commands with root privileges, allowing full takeover of the device. This includes launching services such as Telnet, exfiltrating credentials, modifying system configuration, and disrupting availability. The flaw stems from the lack of authentication and inadequate sanitation of the cmd parameter.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 1, 2025
Updated May 15, 2026
Reserved Aug 1, 2025
CISA Vulnrichment
Updated Aug 4, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a