CVE-2026-4627: D-Link DIR-825/DIR-825R NTP Service libdeuteron_modules.so handler_update_system_time os command injection
A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handlerupdatesystemtime of the file libdeuteronmodules.so of the component NTP Service. The manipulation results in os command injection. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4627?
CVE-2026-4627 is considered a high-severity vulnerability due to its ability to allow remote command injection.
How do I fix CVE-2026-4627?
To fix CVE-2026-4627, update the firmware of D-Link DIR-825 to version 1.0.6 or DIR-825R to version 4.5.2 to mitigate the vulnerability.
What systems are affected by CVE-2026-4627?
CVE-2026-4627 affects D-Link DIR-825 version 1.0.5 and DIR-825R version 4.5.1 routers.
What type of vulnerability is CVE-2026-4627?
CVE-2026-4627 is an OS command injection vulnerability found in the NTP Service of specific D-Link routers.
Can CVE-2026-4627 be exploited remotely?
Yes, CVE-2026-4627 can be exploited remotely without requiring authentication.