← Vulnerability feed

Vulnerability record · CVE-2018-25115 · published 27 August 2025

CVE-2018-25115: Dlink dir-110 firmware os command injection vulnerability

Dlink · Dir 110 Firmware

Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication. The flaw stems from improper input handling in the EVENT=CHECKFW parameter, which is passed directly to the system shell without sanitization. A crafted HTTP POST request can inject commands that are executed with root privileges, resulting in full device compromise. These router models are no longer supported at the time of assignment and affected version ranges may vary. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-08-21 UTC.

10.0 CVSS 4.0 Critical EPSS 10% · top 4.4% CWE-78 · OS command injection
10.0CVSS 4.0 base score
10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication. The flaw stems from improper input handling in the EVENT=CHECKFW parameter, which is passed directly to the system shell without sanitization. A crafted HTTP POST request can inject commands that are executed with root privileges, resulting in full device compromise. These router models are no longer supported at the time of assignment and affected version ranges may vary. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-08-21 UTC.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-25115 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16920D-Link router PingTest CGI command injection allows unauthenticated RCEMultiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sani…KEVEPSS 100%analysed9.8CVE-2014-8361Realtek SDK miniigd SOAP service remote code executionThe miniigd SOAP service in the Realtek SDK fails to properly validate input in a NewInternalClient request, allowing remote code execution. The flaw…KEVEPSS 100%analysed8.8CVE-2020-9377D-Link DIR-610 command.php OS command injectionD-Link DIR-610 firmware passes the cmd parameter to command.php without sanitizing it, allowing OS command injection. The product is end-of-life and …KEVEPSS 21%analysed8.0CVE-2014-100005D-Link DIR-600 router CSRF enables admin account creation and remote managementThe D-Link DIR-600 (rev. Bx) with firmware before 2.17b02 is affected by multiple cross-site request forgery flaws in hedwig.cgi, pigwidgeon.cgi and …KEVEPSS 43%analysed10.0CVE-2013-10069Dlink dir-600 firmware os command injection vulnerabilityThe web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command in…EPSS 17%9.8CVE-2023-33625Dlink dir-600 firmware command injection vulnerabilityD-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxm…EPSS 33%9.8CVE-2023-33626Dlink dir-600 firmware out-of-bounds write vulnerabilityD-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary.EPSS 1.5%9.8CVE-2021-42627D-Link DIR-615 WAN page exposed without authenticationThe WAN configuration page wan.htm on D-Link DIR-615 devices running firmware 20.06 is reachable directly without authentication. An unauthenticated …EPSS 63%analysed

Source: NIST National Vulnerability Database (record CVE-2018-25115), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.