Back

HIGH

D-Link Devices tools_vct.xgi Authenticated RCE

Published Aug 1, 2025

Description

An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly sanitize user-supplied input in the pingIp parameter, allowing attackers with valid credentials to inject arbitrary shell commands. Exploitation enables full device compromise, including spawning a telnet daemon and establishing a root shell. The vulnerability is present in firmware versions that expose tools_vct.xgi and use the Mathopd/1.5p6 web server. No vendor patch is available, and affected models are end-of-life.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 1, 2025
Updated May 26, 2026
Reserved Aug 1, 2025
CISA Vulnrichment
Updated Aug 4, 2025
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a