CVE-2025-44835: Command Injection
Published May 1, 2025
·Updated
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in iptablesWebsFilterRun, which allows remote attackers to execute arbitrary commands via shell.
Affected Software
3 affected components
D-Link DIR-816
All of the following
Dlink Dir-816 A2 Firmware=1.10b05
Dlink Dir-816 A2
Event History
May 1, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Jun 14, 57318
Event
via FIRST·11:59 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-44835?
CVE-2025-44835 is classified as critical due to its potential for remote command execution.
2
How do I fix CVE-2025-44835?
To fix CVE-2025-44835, update the D-Link DIR-816 firmware to the latest version provided by the vendor.
3
What type of vulnerability is CVE-2025-44835?
CVE-2025-44835 is a command injection vulnerability affecting the iptablesWebsFilterRun function.
4
Who is affected by CVE-2025-44835?
Users of the D-Link DIR-816 router are affected by CVE-2025-44835 if they have not applied the necessary patches.
5
Can CVE-2025-44835 be exploited remotely?
Yes, CVE-2025-44835 can be exploited remotely, allowing attackers to execute arbitrary commands.