CVE-2025-25893
published 2025-02-18CVE-2025-25893: An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This…
PriorityP350high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
1.00%
58.8th percentile
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dsl-3782_firmware | — | — |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
ghsa·2026-02-05·CVSS 9.3
CVE-2026-25893 [CRITICAL] CWE-285 FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
### Note
GitHub incorrectly stated this vulnerability is identical to CVE-2025-69970, which describes the fact that authentication is disabled by default. This advisory describes an exploit chain that enables authentication bypass via the heartbeat refresh endpoint when authentication is enabled. This misleads users into thinking that enabling authentication would mitigate this vulnerability. Please see the patch for more information: https://github.com/frangoteam/FUXA/commit/fe82348d160904d0013b9a3e267d50158f5c7afb.
### Description
An authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the heartbeat refresh API and execute arbitrary code on the server. Th
GHSA
GHSA-5pp8-6xcp-c279: An OS command injection vulnerability was discovered in D-Link DSL-3782 v1
ghsa_unreviewed·2025-02-19
CVE-2025-25893 [HIGH] CWE-78 GHSA-5pp8-6xcp-c279: An OS command injection vulnerability was discovered in D-Link DSL-3782 v1
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-18
Published