CVE-2025-4341Injection in Dlink Dir-880l Firmware

Severity
5.3MEDIUMNVD
EPSS
1.3%
top 19.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6

Description

A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. Affected by this vulnerability is the function sub_16570 of the file /htdocs/ssdpcgi of the component Request Header Handler. The manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVER_ID leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5d-link/dir-880l104WWb01

🔴Vulnerability Details

2
GHSA
GHSA-8p6x-2w5r-wvv8: A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb012025-05-06
CVEList
D-Link DIR-880L Request Header ssdpcgi sub_16570 command injection2025-05-06
CVE-2025-4341 — Injection in Dlink Dir-880l Firmware | cvebase