CVE-2025-9026: D-Link DIR-860L Simple Service Discovery Protocol cgibin ssdpcgi_main os command injection
A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgimain of the file htdocs/cgibin of the component Simple Service Discovery Protocol. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9026?
CVE-2025-9026 is classified as a critical vulnerability due to its potential for remote exploitation via OS command injection.
How do I fix CVE-2025-9026?
To mitigate CVE-2025-9026, updating the D-Link DIR-860L firmware to the latest version provided by D-Link is essential.
What type of devices are affected by CVE-2025-9026?
CVE-2025-9026 specifically affects the D-Link DIR-860L router.
Can CVE-2025-9026 be exploited remotely?
Yes, CVE-2025-9026 can be exploited remotely, making it a significant security concern.
What is the nature of the vulnerability in CVE-2025-9026?
CVE-2025-9026 involves OS command injection through the Simple Service Discovery Protocol, allowing unauthorized commands to be executed.