MEDIUM
D-Link DI-500WF jhttpd version_upgrade.asp os command injection
Published Aug 31, 2025
5.1
MEDIUMCVSS 4.0
EPSS 10.22%
Description
A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected products
-
- Version 14.04.10A1TStatusaffectedConstraints-
- Version
AND
- 14.04.10a1t
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26310 Advisory
- https://github.com/physicszq/Routers/blob/main/tmp/01/poc.py exploit
- https://github.com/physicszq/Routers/tree/main/tmp/01 exploitrelated
- https://nvd.nist.gov/vuln/detail/CVE-2025-9745
- https://vuldb.com/?ctiid.322044 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.322044 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.640394 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.dlink.com/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26310 | Advisory | |
| https://github.com/physicszq/Routers/blob/main/tmp/01/poc.py | exploit | |
| https://github.com/physicszq/Routers/tree/main/tmp/01 | exploitrelated | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-9745 | ||
| https://vuldb.com/?ctiid.322044 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.322044 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.640394 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.dlink.com/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 31, 2025
Updated Sep 2, 2025
Reserved Aug 30, 2025
Link CVE-2025-9745
CISA Vulnrichment
Updated Sep 2, 2025
ENISA EUVD
EUVD-2025-26310 Assigner VulDB
Published Apr 29, 2026
Updated Apr 29, 2026
Exploited since n/a
Link EUVD-2025-26310