MEDIUM
D-Link DCS-932L setSystemAdmin os command injection
Published Jun 4, 2025
5.3
MEDIUMCVSS 4.0
EPSS 13.62%
Description
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function setSystemAdmin of the file /setSystemAdmin. The manipulation of the argument AdminID leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected products
-
Affected
- 2.18.01
AND
- 2.18.01
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-16844 Advisory
- https://github.com/wudipjq/my_vuln/blob/main/D-Link5/vuln_42/42.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.311028 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.311028 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.588465 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.dlink.com/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-16844 | Advisory | |
| https://github.com/wudipjq/my_vuln/blob/main/D-Link5/vuln_42/42.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.311028 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.311028 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.588465 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.dlink.com/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jun 4, 2025
Updated Jun 4, 2025
Reserved Jun 3, 2025
Link CVE-2025-5571
CISA Vulnrichment
Updated Jun 4, 2025
Red Hat
No data
GitHub
No data