CVE-2025-25894: OS Command Injection
Published Feb 18, 2025
·Updated
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the sambawg and sambanbn parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.
Affected Software
3 affected components
D-Link DSL-3782
All of the following
Dlink Dsl-3782 Firmware=1.01
Dlink Dsl-3782
Event History
Feb 18, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25894?
CVE-2025-25894 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-25894?
To fix CVE-2025-25894, update the D-Link DSL-3782 firmware to the latest version provided by the vendor.
3
What type of vulnerability is CVE-2025-25894?
CVE-2025-25894 is an OS command injection vulnerability that allows attackers to execute arbitrary commands.
4
Who is affected by CVE-2025-25894?
CVE-2025-25894 affects users of the D-Link DSL-3782 router running version 1.01.
5
Can CVE-2025-25894 be exploited remotely?
Yes, CVE-2025-25894 can be exploited remotely through crafted network packets.