CVE-2025-5620: D-Link DIR-816 setipsec_config os command injection
A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsecconfig of the file /goform/setipsecconfig. The manipulation of the argument localIP/remoteIP leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5620?
CVE-2025-5620 is classified as a critical vulnerability.
What devices are affected by CVE-2025-5620?
CVE-2025-5620 affects the D-Link DIR-816 version 1.10CNB05.
What type of vulnerability is CVE-2025-5620?
CVE-2025-5620 is an OS command injection vulnerability.
How do I fix CVE-2025-5620?
To mitigate CVE-2025-5620, update the firmware of the D-Link DIR-816 to the latest version provided by the manufacturer.
Can CVE-2025-5620 be exploited remotely?
Yes, CVE-2025-5620 can be exploited remotely due to the vulnerable function in the device.