← All CVEs

CVE-2025-44084

critical · 9.8

D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.

9.8
CVSS
20.1%
EPSS (exploit prob.)
97th
EPSS percentile
2025-05-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
dlinkdi-8100g_firmware16.07.26a1
dlinkdi-8100all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-44084