D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided by cgibin does not filter the HTTP SOAPAction header field. The unauthenticated remote attacker can execute the shell command.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink dir-868l
Dlink dir-868l Firmware |
|
| CPEs | cpe:2.3:h:dlink:dir-868l:a1:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-868l_firmware:fw106krb01:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink dir-868l
Dlink dir-868l Firmware |
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dir-868l A1 |
|
| Vendors & Products |
Dlink
Dlink dir-868l A1 |
Thu, 20 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 | |
| Metrics |
cvssV3_1
|
Wed, 19 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided by cgibin does not filter the HTTP SOAPAction header field. The unauthenticated remote attacker can execute the shell command. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-19T00:00:00.000Z
Updated: 2025-11-20T15:39:00.429Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63932
Updated: 2025-11-20T15:03:04.307Z
Status : Analyzed
Published: 2025-11-19T20:15:53.817
Modified: 2025-12-11T18:23:31.007
Link: CVE-2025-63932
No data.