← Vulnerability feed

Vulnerability record · CVE-2025-4340 · published 6 May 2025

CVE-2025-4340: Dlink dir-806 firmware injection vulnerability

Dlink · Dir 806 Firmware

A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

5.3 CVSS 4.0 Medium EPSS 4.9% · top 8.2% CWE-74 · InjectionCWE-77 · Command injection
5.3CVSS 4.0 base score, v2 6.5
4.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/CH13hh/tmp_store_cc/blob/main/tt/1.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.307458 Permissions RequiredVDB Entry
https://vuldb.com/?id.307458 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.556092 Third Party AdvisoryVDB Entry
https://www.dlink.com/ Product
https://github.com/CH13hh/tmp_store_cc/blob/main/tt/1.md ExploitThird Party Advisory

Track CVE-2025-4340 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-17621D-Link DIR-859 UPnP gena.cgi unauthenticated command injectionThe UPnP endpoint /gena.cgi on D-Link DIR-859 firmware 1.05 and 1.06B01 Beta01 fails to sanitize input in an HTTP SUBSCRIBE request, allowing OS comm…KEVEPSS 90%analysed9.8CVE-2023-43130Dlink dir-806 firmware os command injection vulnerabilityD-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection.EPSS 2.8%9.8CVE-2023-43129Dlink dir-806 firmware os command injection vulnerabilityD-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of REMOTE_PORT parameters.EPSS 2.8%9.8CVE-2023-43128Dlink dir-806 firmware command injection vulnerabilityD-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of HTTP_ST parameters.EPSS 2.8%9.8CVE-2022-30521Dlink dir-890l firmware out-of-bounds write vulnerabilityThe LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b0…EPSS 15%9.8CVE-2017-14948Dlink dir-868l firmware classic buffer overflow vulnerabilityCertain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary cod…EPSS 4.9%9.8CVE-2019-10891Dlink dir-806 firmware os command injection vulnerabilityAn issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls system() without checking the para…EPSS 19%9.8CVE-2019-10892Dlink dir-806 firmware out-of-bounds write vulnerabilityAn issue was discovered in D-Link DIR-806 devices. There is a stack-based buffer overflow in function hnap_main at /htdocs/cgibin. The function will …EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2025-4340), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.