CVE-2018-25115

CRITICAL EPSS 94.5%
Published Aug 27, 202510mo ago · Modified Jun 17, 20261w ago
10.0 CVSS 4.0
Critical
Find Similar
Published Aug 27, 2025 10mo ago
Last Modified Jun 17, 2026 1w ago

Description

Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication. The flaw stems from improper input handling in the EVENT=CHECKFW parameter, which is passed directly to the system shell without sanitization. A crafted HTTP POST request can inject commands that are executed with root privileges, resulting in full device compromise. These router models are no longer supported at the time of assignment and affected version ranges may vary. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-08-21 UTC.

CVSS Details

Base Score
10.0
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
94.5% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available

Weaknesses 1

CWE-78 OS Command Injection Injection

Affected Products 14

VendorProductVersionRange
dlinkdir-110_firmware*any
dlinkdir-110*any
dlinkdir-412_firmware*any
dlinkdir-412*any
dlinkdir-600_firmware*any
dlinkdir-600*any
dlinkdir-610_firmware*any
dlinkdir-610*any
dlinkdir-615_firmware*any
dlinkdir-615*any
dlinkdir-645_firmware*any
dlinkdir-645*any
dlinkdir-815_firmware1.03any
dlinkdir-815*any

References 5

  • github.com https://github.com/Cr0n1c/dlink_shell_poc/blob/master/dlink_auth_rce
    Exploit
  • legacy.us.dlink.com https://legacy.us.dlink.com/
    Product
  • support.dlink.com https://support.dlink.com/EndOfLifePolicy.aspx
    Product
  • exploit-db.com https://www.exploit-db.com/exploits/43496
    Exploit
  • vulncheck.com https://www.vulncheck.com/advisories/dlink-dir-rce-service-cgi
    Third Party Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.