VYPR
Unrated severityNVD Advisory· Published May 6, 2025· Updated May 6, 2025

D-Link DIR-890L/DIR-806A1 soap.cgi sub_175C8 command injection

CVE-2025-4340

Description

Critical command injection in D-Link DIR-890L and DIR-806A1 via sub_175C8 in soap.cgi allows remote code execution on unsupported devices.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Critical command injection in D-Link DIR-890L and DIR-806A1 via `sub_175C8` in soap.cgi allows remote code execution on unsupported devices.

Vulnerability

A critical command injection vulnerability exists in the sub_175C8 function within the /htdocs/soap.cgi file of D-Link DIR-890L and DIR-806A1 routers running firmware versions up to 100CNb11 and 108B03, respectively. The vulnerability allows an attacker to inject arbitrary commands through crafted SOAP requests. This issue affects only products that are no longer supported by the vendor [1].

Exploitation

An attacker can exploit this vulnerability remotely without authentication by sending a specially crafted SOAP request to the affected router's soap.cgi endpoint. The injection occurs within the sub_175C8 function, which does not properly sanitize user input. Public exploit code has been disclosed, making exploitation straightforward for attackers with network access to the device.

Impact

Successful exploitation allows an attacker to execute arbitrary commands on the affected router with root privileges, leading to full device compromise. This can result in information disclosure, denial of service, or use of the device as a pivot point in further attacks.

Mitigation

No official patch is available as these products have reached end-of-life and are no longer supported by D-Link. Users are strongly advised to replace affected devices with supported models. As a temporary measure, access to the SOAP interface should be restricted by firewall rules and disabled if not needed. The vulnerability is not listed on CISA KEV as of publication.

References
  1. Landing

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • Dlink/DIR-806llm-create2 versions
    <=108B03+ 1 more
    • (no CPE)range: <=108B03
    • (no CPE)range: 100CNb11
  • Dlink/DIR-890Lllm-fuzzy2 versions
    <=100CNb11+ 1 more
    • (no CPE)range: <=100CNb11
    • (no CPE)range: 100CNb11

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.