A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via `nvram_safe_set("dmz_ipaddr", ...)`. These values are later retrieved in the `DMZ_run` function of `librcm.so` using `nvram_safe_get` and concatenated into `iptables` shell commands executed via `twsystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Nov 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:h:dlink:dir-882:a1:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-882_firmware:1.02b02:*:*:*:*:*:*:* |
Fri, 14 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Fri, 14 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dir-882 Dlink dir-882 Firmware |
|
| Vendors & Products |
Dlink
Dlink dir-882 Dlink dir-882 Firmware |
Thu, 13 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via `nvram_safe_set("dmz_ipaddr", ...)`. These values are later retrieved in the `DMZ_run` function of `librcm.so` using `nvram_safe_get` and concatenated into `iptables` shell commands executed via `twsystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-13T00:00:00.000Z
Updated: 2025-11-14T16:15:58.120Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60700
Updated: 2025-11-14T16:15:51.025Z
Status : Analyzed
Published: 2025-11-13T18:15:54.010
Modified: 2025-11-17T12:28:40.547
Link: CVE-2025-60700
No data.