CVE-2025-29041: OS Command Injection
Published Apr 17, 2025
·Updated
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the targetaddr key value and the function 0x41710c
Affected Software
3 affected components
D-Link DIR 832X
All of the following
Dlink Dir-823x Firmware=240802
Dlink Dir-823x
Event History
Apr 17, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-29041?
CVE-2025-29041 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-29041?
To fix CVE-2025-29041, update your D-Link DIR 832X to the latest firmware version provided by D-Link.
3
What kind of attack is CVE-2025-29041 associated with?
CVE-2025-29041 allows remote attackers to execute arbitrary code via manipulation of the target_addr key value.
4
What devices are affected by CVE-2025-29041?
CVE-2025-29041 specifically affects the D-Link DIR 832X router model.
5
What potential outcomes can occur if CVE-2025-29041 is exploited?
Exploitation of CVE-2025-29041 may lead to a complete compromise of the affected device, allowing attackers to execute arbitrary code.