CVE-2025-9745
low · 2A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
2
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2025-08-31
Published
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses
CWE-77CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| dlink | di-500wf_firmware | 14.04.10a1t |
| dlink | di-500wf | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/physicszq/Routers/blob/main/tmp/01/poc.py
- https://github.com/physicszq/Routers/tree/main/tmp/01
- https://vuldb.com/?ctiid.322044
- https://vuldb.com/?id.322044
- https://vuldb.com/?submit.640394
- https://www.dlink.com/
- https://github.com/physicszq/Routers/blob/main/tmp/01/poc.py
- https://github.com/physicszq/Routers/tree/main/tmp/01
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-9745