← Back to browse · API

CVE-2025-55583

Severity
CRITICAL
CVSS
9.8
EPSS
0.0583
Risk score
41.24
CISA KEV
No
PoC
No
Published
2025-08-28
Modified
2025-08-28
First seen
2026-08-07
Aliases
EUVD-2025-26076, GHSA-JPV7-G9GX-62X7
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-26076

Description

D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitization or authentication. Remote attackers can exploit this to execute arbitrary commands as root via crafted HTTP requests.

References