CVE-2025-60672: Command Injection
An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' parameters in prog.cgi are stored in NVRAM and later used by rc to construct system commands executed via twsystem(). An attacker can exploit this vulnerability remotely without authentication by sending a specially crafted HTTP request, leading to arbitrary command execution on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60672?
CVE-2025-60672 is classified as a high severity vulnerability due to its potential for unauthenticated command injection.
How do I fix CVE-2025-60672?
To resolve CVE-2025-60672, users should update to the latest firmware version provided by D-Link for the DIR-878A1 router.
What products are affected by CVE-2025-60672?
CVE-2025-60672 specifically affects the D-Link DIR-878A1 router with firmware version FW101B04.bin.
What type of vulnerability is CVE-2025-60672?
CVE-2025-60672 is classified as a command injection vulnerability that can be exploited without authentication.
Is it necessary to have administrative access to exploit CVE-2025-60672?
No, CVE-2025-60672 can be exploited without needing administrative access, making it particularly dangerous.