CVE-2025-60672
Last modified
CVE-2025-60672 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' parameters in prog.cgi are stored in NVRAM and later used by rc to construct system commands executed via twsystem(). EPSS estimates a 3.67% chance of exploitation in the next 30 days.
Description
An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' parameters in prog.cgi are stored in NVRAM and later used by rc to construct system commands executed via twsystem(). An attacker can exploit this vulnerability remotely without authentication by sending a specially crafted HTTP request, leading to arbitrary command execution on the device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-878 Firmware | 1.01b04 |
References
- https://github.com/yifan20020708/SGTaint-0-day/blob/main/DLink/DLink-DIR-878/CVE-2025-60672.mdExploit, Third Party Advisory
- https://www.dlink.com/enProduct
- https://www.dlink.com/en/security-bulletin/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-60672?
How severe is CVE-2025-60672?
How do I fix CVE-2025-60672?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-60660Tenda AC18 V15.03.05.19 was discovered to contain a stack ov…7.5
- CVE-2025-60661Tenda AC18 V15.03.05.19 was discovered to contain a stack ov…5.3
- CVE-2025-60662Tenda AC18 V15.03.05.19 was discovered to contain a stack ov…7.5
- CVE-2025-60663Tenda AC18 V15.03.05.19 was discovered to contain a stack ov…7.5
- CVE-2025-6067The Easy Social Feed – Social Photos Gallery – Post Feed – L…6.4
- CVE-2025-60671A command injection vulnerability exists in the D-Link DIR-8…5.4
- CVE-2025-60673An unauthenticated command injection vulnerability exists in…6.5
- CVE-2025-60674A stack buffer overflow vulnerability exists in the D-Link D…6.8
- CVE-2025-60675A command injection vulnerability exists in the D-Link DIR-8…5.4
- CVE-2025-60676An unauthenticated command injection vulnerability exists in…6.5
- CVE-2025-60679A stack buffer overflow vulnerability exists in the D-Link D…8.8
- CVE-2025-6068The FooGallery – Responsive Photo Gallery, Image Viewer, Jus…5.4
Are you affected by CVE-2025-60672?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
