CVE-2025-60673: Command Injection
An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDMZSettings' functionality, where the 'IPAddress' parameter in prog.cgi is stored in NVRAM and later used by librcm.so to construct iptables commands executed via twsystem(). An attacker can exploit this vulnerability remotely without authentication by sending a specially crafted HTTP request, leading to arbitrary command execution on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60673?
CVE-2025-60673 has a high severity rating due to its potential for unauthenticated command injection.
How do I fix CVE-2025-60673?
To fix CVE-2025-60673, update the D-Link DIR-878A1 router firmware to the latest version provided by D-Link.
What versions of D-Link DIR-878A1 are affected by CVE-2025-60673?
CVE-2025-60673 affects the D-Link DIR-878A1 router firmware version FW101B04.bin.
What potential impact does CVE-2025-60673 have on affected systems?
CVE-2025-60673 can allow an attacker to execute arbitrary commands on the affected router, compromising its integrity.
Are there any workarounds for CVE-2025-60673?
Currently, disabling remote management and changing default settings are recommended as temporary workarounds for CVE-2025-60673.