D-Link DIR-645 ssdpcgi cgibin ssdpcgi_main command injection

CVE Details

Basic Information

Title D-Link DIR-645 ssdpcgi cgibin ssdpcgi_main command injection
Type cve
Published 2025-07-08T19:32:06.193Z
Modified 2025-07-08T19:32:06.193Z

Product Information

Vendor D-Link
Product DIR-645
Version 1.05B01

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A critical vulnerability in D-Link DIR-645 routers (up to version 1.05B01) allows remote command injection via the ssdpcgi_main function. This issue can be exploited remotely, and the product is no longer supported by the vendor.
AI Severity High
AI Vendor D-Link
AI Product D-Link DIR-645
AI Version 1.05B01

Affected Products

  • D-Link DIR-645 1.05B01

Additional Information

CWE List CWE-77, CWE-74
Source VulDB

Description

A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.