cbcvebase.
CVE-2025-10629
published 2025-09-18

CVE-2025-10629: A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file htodcs/cgibin of the component Simple…

PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
5.36%
91.7th percentile
A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file htodcs/cgibin of the component Simple Service Discovery Protocol Service. Executing manipulation of the argument ST can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.

Affected

2 ranges
VendorProductVersion rangeFixed in
d-linkdir-852
dlinkdir-852_firmware

Detection & IOCsextracted from sources · hover to see the quote

port1900/udp
urlhttps://github.com/i-Corner/cve/issues/30
pathhtodcs/cgibin
processssdpcgi_main
snort
alert udp any any -> $HOME_NET 1900 (msg:"ET WEB_SPECIFIC_APPS D-Link SSDP ST Header Command Injection Attempt (CVE-2025-10629, CVE-2026-3485)"; flow:established,to_server; content:"M-SEARCH "; depth:9; fast_pattern; content:"ST|3a|"; distance:0; pcre:"/^[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; reference:url,github.com/i-Corner/cve/issues/30; reference:cve,2025-10629; reference:cve,2026-3485; classtype:attempted-admin; sid:2064797; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_09_18, cve CVE_2025_10629, deployment Perimeter, deployment Internal, performance_impact Moderate, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_09_18, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
  • Detect SSDP M-SEARCH requests on UDP/1900 where the ST header contains shell metacharacters indicative of command injection: semicolons (;/%3B), newlines (\n/%0A), backticks (`/%60), pipes (|/%7C), or dollar signs ($/%24)
  • Focus detection on the ST header field within SSDP M-SEARCH packets; the vulnerable argument is ST passed to ssdpcgi_main in htodcs/cgibin
  • The attack is remotely exploitable over the network targeting SSDP (UDP port 1900); deploy detection at both perimeter and internal network boundaries
  • Traffic is plaintext (no TLS); filter on UDP/1900 with M-SEARCH method and inspect ST header value for injection characters
  • ·This vulnerability only affects D-Link DIR-852 1.00CN B09, a product that is end-of-life and no longer supported by the maintainer; no patch will be issued
  • ·The Snort/Suricata rule (ET sid:2064797) uses flow:established which may need tuning for stateless UDP SSDP traffic depending on sensor configuration

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.