CVE-2025-10689
Last modified
CVE-2025-10689 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. EPSS estimates a 4.56% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the argument service leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-645 Firmware | 1.05b01 |
References
- https://github.com/scanleale/IOT_sec/blob/main/DIR-645-soapcgi.pdfExploit, Third Party Advisory
- https://vuldb.com/?ctiid.324813Permissions Required, VDB Entry
- https://vuldb.com/?id.324813Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.653689Third Party Advisory, VDB Entry
- https://www.dlink.com/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-10689?
How severe is CVE-2025-10689?
How do I fix CVE-2025-10689?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-10683The Easy Email Subscription plugin for WordPress is vulnerab…4.9
- CVE-2025-10684The Construction Light WordPress theme before 1.6.8 does not…4.3
- CVE-2025-10685Heap-based buffer overflow vulnerability in Softing Industri…7.7
- CVE-2025-10686The Creta Testimonial Showcase WordPress plugin before 1.2.4…7.2
- CVE-2025-10687A vulnerability was found in SourceCodester Responsive E-Lea…9.8
- CVE-2025-10688A vulnerability was determined in SourceCodester Pet Groomin…9.8
- CVE-2025-10690The Goza - Nonprofit Charity WordPress Theme theme for WordP…9.8
- CVE-2025-10691The Easy Email Subscription plugin for WordPress is vulnerab…4.3
- CVE-2025-10692The endpoint POST /api/staff/get-new-tickets concatenates th…7.1
- CVE-2025-10693When SmartStart Inclusion fails during the onboarding of a Z…7.6
- CVE-2025-10694The User Feedback – Create Interactive Feedback Form, User S…5.3
- CVE-2025-10695Two unauthenticated diagnostic endpoints allow arbitrary bac…5.3
Are you affected by CVE-2025-10689?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
