CVE-2025-34048: D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read
A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN1.02, SEA1.04, and SEA1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34048?
CVE-2025-34048 is considered a high-severity vulnerability due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2025-34048?
To fix CVE-2025-34048, users should update the firmware of their D-Link routers to the latest version provided by the manufacturer.
What products are affected by CVE-2025-34048?
CVE-2025-34048 affects D-Link DSL-2730U, DSL-2750U, and DSL-2750E routers running specific firmware versions.
What type of attack can exploit CVE-2025-34048?
CVE-2025-34048 can be exploited through path traversal attacks, allowing attackers to access restricted files on the affected router.
Is CVE-2025-34048 remotely exploitable?
Yes, CVE-2025-34048 is remotely exploitable, enabling malicious actors to potentially compromise the device from anywhere with network access.