CVE-2025-25893: OS Command Injection
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25893?
CVE-2025-25893 is classified as a critical vulnerability due to its potential to allow arbitrary command execution.
How do I fix CVE-2025-25893?
To fix CVE-2025-25893, update the D-Link DSL-3782 to the latest firmware version provided by D-Link.
What systems are affected by CVE-2025-25893?
CVE-2025-25893 affects D-Link DSL-3782 devices running version 1.01.
What attack vector is used in CVE-2025-25893?
CVE-2025-25893 can be exploited through crafted packets that manipulate the inIP, insPort, inePort, exsPort, exePort, and protocol parameters.
Can CVE-2025-25893 be exploited remotely?
Yes, CVE-2025-25893 can be exploited remotely if the affected D-Link DSL-3782 device is accessible over the internet.