CVE-2025-9387: DCN DCME-720 Web Management Backend ip_block.php os command injection
A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ipblock.php of the component Web Management Backend. Performing manipulation of the argument ip results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Other products might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9387?
CVE-2025-9387 is classified as a critical severity vulnerability due to the potential for OS command injection.
How do I fix CVE-2025-9387?
To fix CVE-2025-9387, it is recommended to update to the latest firmware of DCN DCME-720 that addresses this vulnerability.
What components are affected by CVE-2025-9387?
CVE-2025-9387 affects the web management backend, specifically the ip_block.php file.
Can CVE-2025-9387 result in data compromise?
Yes, CVE-2025-9387 can lead to unauthorized command execution, potentially compromising system data.
What actions should be taken if CVE-2025-9387 is exploited?
If CVE-2025-9387 is exploited, immediate measures should include isolating the affected system and conducting a thorough security assessment.