cbcvebase.
CVE-2025-9752
published 2025-09-01

CVE-2025-9752: A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP…

PriorityP278critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
15.82%
96.5th percentile
A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

Affected

2 ranges
VendorProductVersion rangeFixed in
d-linkdir-852
dlinkdir-852_firmware

Detection & IOCsextracted from sources · hover to see the quote

path/soap.cgi
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link soap.cgi service Parameter Command Injection Attempt (CVE-2025-9752)"; flow:established,to_server; http.uri; content:"/soap.cgi|3f|"; fast_pattern; content:"service|3d|"; pcre:"/^[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; reference:url,github.com/scanleale/IOT_sec/blob/main/DIR-816L.pdf; reference:cve,2025-9752; classtype:attempted-admin; sid:2065798; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_11_17, cve CVE_2025_9752, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_11_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
  • Target HTTP requests to /soap.cgi with a `service` query parameter containing OS command injection metacharacters: semicolon (;/%3B), newline (\n/%0A), backtick (`/%60), pipe (|/%7C), or dollar sign ($/%24).
  • Exploitation is remote, unauthenticated, and targets the SOAP service via the `soapcgi_main` function in `soap.cgi`; monitor inbound HTTP traffic to networking equipment on perimeter and internal segments.
  • Traffic is expected in plaintext (non-TLS); prioritize inspection on plain HTTP flows to D-Link DIR-852 devices.
  • MITRE mapping: Initial Access (TA0001) via Exploit Public-Facing Application (T1190); treat alerts as attempted-admin severity.
  • ·The vulnerability only affects end-of-life hardware (D-Link DIR-852 1.00CN B09); no vendor patch will be issued. Affected devices should be isolated or replaced.
  • ·The ET rule (sid:2065798) references a DIR-816L PDF for context, but the CVE targets the DIR-852; verify applicability if deploying the rule against DIR-816L devices.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.