An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.
Metrics
Affected Vendors & Products
References
History
Fri, 02 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dsl-3782 Dlink dsl-3782 Firmware |
|
| CPEs | cpe:2.3:h:dlink:dsl-3782:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dsl-3782_firmware:1.01:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink
Dlink dsl-3782 Dlink dsl-3782 Firmware |
Wed, 19 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 | |
| Metrics |
cvssV3_1
|
Tue, 18 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-02-18T00:00:00.000Z
Updated: 2025-02-19T15:58:17.832Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25893
Updated: 2025-02-19T15:58:06.682Z
Status : Analyzed
Published: 2025-02-18T22:15:18.920
Modified: 2025-05-02T15:46:13.270
Link: CVE-2025-25893
No data.