CVE-2025-15391: D-Link DIR-806A SSDP Request ssdpcgi_main command injection
A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgimain of the component SSDP Request Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15391?
CVE-2025-15391 is classified as a high-severity vulnerability due to the risk of remote command injection.
How do I fix CVE-2025-15391?
To fix CVE-2025-15391, update the firmware of the D-Link DIR-806A to the latest version provided by the vendor.
What does CVE-2025-15391 affect?
CVE-2025-15391 affects the SSDP Request Handler function ssdpcgi_main in the D-Link DIR-806A router.
Can CVE-2025-15391 be exploited remotely?
Yes, CVE-2025-15391 can be exploited remotely, allowing attackers to manipulate the device.
Is there a public exploit available for CVE-2025-15391?
Yes, an exploit for CVE-2025-15391 has been made publicly available.