CVE-2025-7932

A vulnerability classified as critical has been found in D-Link DIR‑817L up to 1.04B01. This affects the function lxmldbc_system of the file ssdpcgi. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dir-817l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-817l:-:*:*:*:*:*:*:*

History

03 Oct 2025, 18:39

Type Values Removed Values Added
First Time Dlink
Dlink dir-817l Firmware
Dlink dir-817l
CPE cpe:2.3:o:dlink:dir-817l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-817l:-:*:*:*:*:*:*:*
Summary
  • (es) Se ha detectado una vulnerabilidad clasificada como crítica en D-Link DIR?817L hasta la versión 1.04B01. Esta afecta a la función lxmldbc_system del archivo ssdpcgi. La manipulación provoca la inyección de comandos. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado.
References () https://github.com/Patr1ck-S/Patr1ck-S.github.io/blob/main/D-Link%20DIR%E2%80%91817L%20has%20a%20remote%20arbitrary%20command%20execution%20vulnerability%20in%20ssdpcgi(1).md - () https://github.com/Patr1ck-S/Patr1ck-S.github.io/blob/main/D-Link%20DIR%E2%80%91817L%20has%20a%20remote%20arbitrary%20command%20execution%20vulnerability%20in%20ssdpcgi(1).md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.317061 - () https://vuldb.com/?ctiid.317061 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.317061 - () https://vuldb.com/?id.317061 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.618951 - () https://vuldb.com/?submit.618951 - Third Party Advisory, VDB Entry
References () https://www.dlink.com/ - () https://www.dlink.com/ - Product

21 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 17:15

Updated : 2025-10-03 18:39


NVD link : CVE-2025-7932

Mitre link : CVE-2025-7932

CVE.ORG link : CVE-2025-7932


JSON object : View

Products Affected

dlink

  • dir-817l_firmware
  • dir-817l
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')