VYPR
Unrated severityNVD Advisory· Published May 6, 2025· Updated May 6, 2025

D-Link DIR-600L formSysCmd command injection

CVE-2025-4349

Description

A vulnerability classified as critical has been found in D-Link DIR-600L up to 2.07B01. This affects the function formSysCmd. The manipulation of the argument host leads to command injection. It is possible to initiate the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.

Affected products

2
  • Dlink/DIR600Lllm-create
    Range: <= 2.07B01
  • D-Link/DIR-600Lv5
    Range: 2.07B01

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.