CVE-2025-60675: Command Injection
A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823GV1.0.2B0520181207.bin in the timelycheck and sysconf binaries, which process the /tmp/newqos.rule configuration file. The vulnerability occurs because parsed fields from the configuration file are concatenated into command strings and executed via system() without any sanitization. An attacker with write access to /tmp/newqos.rule can execute arbitrary commands on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60675?
CVE-2025-60675 is a high severity command injection vulnerability affecting D-Link DIR-823G router firmware.
What systems are affected by CVE-2025-60675?
CVE-2025-60675 specifically affects the D-Link DIR-823G router running firmware version V1.0.2B05_20181207.
How do I fix CVE-2025-60675?
To resolve CVE-2025-60675, users should update their D-Link DIR-823G routers to the latest firmware version provided by D-Link.
What are the consequences of exploiting CVE-2025-60675?
Exploiting CVE-2025-60675 could allow an attacker to execute arbitrary commands on the vulnerable D-Link router.
When was CVE-2025-60675 disclosed?
CVE-2025-60675 was disclosed in 2025 and affects specific versions of D-Link firmware.