CVE 5.1 MEDIUM

D-Link DI-500WF jhttpd version_upgrade.asp os command injection_CVE-2025-9745

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

Basic Information

ID CVE-2025-9745
Source VulDB
Published Aug 31, 2025 at 20:32

Affected Product

Vendor D-Link
Product DI-500WF
Version 14.04.10A1T
Affected Versions D-Link DI-500WF 14.04.10A1T

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.