CNNVD-202508-3698 Information

CNNVD ID

CNNVD-202508-3698

CVE-2025-9745

  • CNNVD Published: 2025-08-31

Description (Chinese)

D-Link DI-500WF是中国友讯(D-Link)公司的一款面板式无线接入点。 D-Link DI-500WF 14.04.10A1T版本存在安全漏洞,该漏洞源于对文件/version_upgrade.asp中参数path的错误操作导致os命令注入攻击。

Description (English)

D-Link DI-500WF is a panel-based wireless access point for the Chinese company D-Link. The D-Link DI-500WF 14.04.10A1T version has a security loophole, which stems from an error in the operation of the parameter path in the document/version upgrade.asp, resulting in an Os command injection attack.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

D3D

Published

2025-08-31

Last Modified

2026-02-24

References

https://www.dlink.com/ https://vuldb.com/?submit.640394 https://vuldb.com/?id.322044 https://vuldb.com/?ctiid.322044 https://github.com/physicszq/Routers/tree/main/tmp/01 https://github.com/physicszq/Routers/blob/main/tmp/01/poc.py https://access.redhat.com/security/cve/cve-2025-9745 https://nvd.nist.gov/vuln/detail/CVE-2025-9745

Share on: