CVE-2025-8956: D-Link DIR‑818L ssdpcgi cgibin getenv command injection
A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8956?
CVE-2025-8956 is classified as a high severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2025-8956?
To fix CVE-2025-8956, upgrade the D-Link DIR-818L firmware to a version newer than 1.05B01.
Who is affected by CVE-2025-8956?
CVE-2025-8956 affects users of the D-Link DIR-818L router running firmware version 1.05B01 or earlier.
What types of attacks can be executed using CVE-2025-8956?
CVE-2025-8956 allows attackers to execute arbitrary commands on the affected device remotely.
Is CVE-2025-8956 publicly disclosed?
Yes, CVE-2025-8956 has been disclosed to the public, making it critical for users to patch their devices.