CNNVD-202507-2524 Information

CNNVD ID

CNNVD-202507-2524

CVE-2025-7836

  • CNNVD Published: 2025-07-19

Description (Chinese)

D-Link DIR-816L是中国友讯(D-Link)公司的一款无线路由器。 D-Link DIR-816L 2.06B01及之前版本存在注入漏洞,该漏洞源于环境变量处理组件中lxmldbc_system函数存在命令注入。

Description (English)

D-Link DIR-816L is a wireless router of D-Link. The D-Link DIR-816L 2.06B01 and previous versions have an injection loophole, resulting from the presence of command injections in the lxmldbc system function in the environmental variable processing component.

Hazard Level

High

Vulnerability Type

注入

Affected Vendor

友讯

Published

2025-07-19

Last Modified

2026-02-24

References

https://vuldb.com/?id.316939 https://vuldb.com/?ctiid.316939 https://www.dlink.com/ https://github.com/bananashipsBBQ/CVE/blob/main/D-Link%20DIR-816L%20Remote%20Arbitrary%20Command%20Execution%20Vulnerability%20in%20ssdpcgi.md https://vuldb.com/?submit.617359 https://access.redhat.com/security/cve/cve-2025-7836

Share on: