CVE-2025-60344: Infoleak
A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as “../”). Successful exploitation may allow access to files outside of the intended directory, potentially exposing sensitive system or configuration files. The issue results from insufficient validation or sanitization of user-supplied input. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32WW.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60344?
CVE-2025-60344 is classified as a high-severity vulnerability due to its potential to expose sensitive configuration files.
How does CVE-2025-60344 impact affected D-Link DSR routers?
CVE-2025-60344 allows unauthorized remote attackers to retrieve sensitive files that contain administrative credentials and other critical information.
What versions of D-Link routers are vulnerable to CVE-2025-60344?
D-Link DSR-150, DSR-150N, and DSR-250N are among the affected models in CVE-2025-60344.
How can users mitigate the risks associated with CVE-2025-60344?
Users should limit access to the router's management interface and apply security updates provided by D-Link.
Is CVE-2025-60344 an authenticated or unauthenticated vulnerability?
CVE-2025-60344 is an unauthenticated Local File Inclusion vulnerability, meaning it can be exploited without prior authentication.