MEDIUM
D-Link DCS-932L setSystemWizard setSystemControl os command injection
Published Jun 4, 2025
5.3
MEDIUMCVSS 4.0
EPSS 13.77%
Description
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been rated as critical. Affected by this issue is the function setSystemWizard/setSystemControl of the file /setSystemWizard. The manipulation of the argument AdminID leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected products
-
Affected
- 2.18.01
AND
- 2.18.01
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-16839 Advisory
- https://github.com/wudipjq/my_vuln/blob/main/D-Link5/vuln_44/44.md exploit
- https://vuldb.com/?ctiid.311030 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.311030 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.588467 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.dlink.com/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-16839 | Advisory | |
| https://github.com/wudipjq/my_vuln/blob/main/D-Link5/vuln_44/44.md | exploit | |
| https://vuldb.com/?ctiid.311030 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.311030 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.588467 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.dlink.com/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jun 4, 2025
Updated Jun 4, 2025
Reserved Jun 3, 2025
Link CVE-2025-5573
CISA Vulnrichment
Updated Jun 4, 2025
Red Hat
No data
GitHub
No data