cbcvebase.
CVE-2025-13562
published 2025-11-23

CVE-2025-13562: A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi. Such manipulation of the argument…

PriorityP272critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.73%
92.2th percentile
A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi. Such manipulation of the argument service leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.

Affected

2 ranges
VendorProductVersion rangeFixed in
d-linkdir-852
dlinkdir-852_firmware

Detection & IOCsextracted from sources · hover to see the quote

path/gena.cgi
snort
alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link gena.cgi service Parameter Command Injection Attempt (CVE-2025-13562, CVE-2024-23624, CVE-2019-17621)"; flow:established,to_server; content:"SUBSCRIBE /gena.cgi|3f|service|3d|"; fast_pattern; depth:28; pcre:"/^[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; content:"NT|3a 20|"; content:"Callback|3a 20|"; reference:cve,2019-17621; reference:cve,2025-13562; reference:cve,2024-23624; classtype:attempted-admin; sid:2066991; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2026_01_23, cve CVE_2019_17621, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2026_01_23, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
  • Exploit traffic uses HTTP SUBSCRIBE method targeting /gena.cgi with a 'service' query parameter; look for shell metacharacters (;, newline, backtick, pipe, $) injected into the service value
  • Exploit requests also contain both 'NT:' and 'Callback:' HTTP headers, consistent with UPnP SUBSCRIBE abuse; filter on co-presence of these headers with the malicious service parameter
  • Attack is plaintext (no TLS), inbound from external networks to internal/perimeter D-Link networking equipment; deploy detection at perimeter and internal chokepoints
  • The exploit is publicly available; treat any SUBSCRIBE /gena.cgi?service= request from untrusted sources as high-confidence attempted admin compromise (MITRE T1190)
  • ·The Snort/ET rule covers three CVEs simultaneously (CVE-2025-13562, CVE-2024-23624, CVE-2019-17621); a positive alert does not by itself distinguish which CVE is being exploited
  • ·Affected product (D-Link DIR-852 1.00) is end-of-life and will receive no vendor patch; detection/blocking is the only available mitigation

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.