ID

VAR-202511-1433


CVE

CVE-2025-60697


DESCRIPTION

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_4438A4` function in `prog.cgi` stores user-supplied DDNS parameters (`ServerAddress` and `Hostname`) in NVRAM via `nvram_safe_set`. These values are later retrieved in the `start_DDNS_ipv4` function of `rc` using `nvram_safe_get` and concatenated into DDNS shell commands executed via `twsystem()` without proper sanitization. Partial string comparison is performed but is insufficient to prevent command injection. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.

Trust: 1.0

sources: NVD: CVE-2025-60697

AFFECTED PRODUCTS

vendor:dlinkmodel:dir-882scope:eqversion:1.02b02

Trust: 1.0

sources: NVD: CVE-2025-60697

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-60697
value: HIGH

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-60697
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 3.9
impactScore: 3.4
version: 3.1

Trust: 1.0

sources: NVD: CVE-2025-60697

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.0

sources: NVD: CVE-2025-60697

EXTERNAL IDS

db:NVDid:CVE-2025-60697

Trust: 1.0

sources: NVD: CVE-2025-60697

REFERENCES

url:https://github.com/yifan20020708/sgtaint-0-day/blob/main/dlink/dlink-dir-882/4.md

Trust: 1.0

url:https://www.dlink.com/

Trust: 1.0

url:https://www.dlink.com/en/security-bulletin/

Trust: 1.0

url:https://github.com/yifan20020708/sgtaint-0-day/blob/main/dlink/dlink-dir-882/cve-2025-60697.md

Trust: 1.0

sources: NVD: CVE-2025-60697

SOURCES

db:NVDid:CVE-2025-60697

LAST UPDATE DATE

2025-11-20T19:40:19.370000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2025-60697date:2025-11-17T12:29:07.143

SOURCES RELEASE DATE

db:NVDid:CVE-2025-60697date:2025-11-13T18:15:53.753