← Back to browse · API

CVE-2025-69542

Severity
CRITICAL
CVSS
9.8
EPSS
0.08575
Risk score
42.2
CISA KEV
No
PoC
No
Published
2026-01-09
Modified
2026-01-12
First seen
2026-08-07
Aliases
EUVD-2026-1712, GHSA-75MQ-3GF9-64WC
Products
n/a:n/a n/a
Sources
euvd EUVD-2026-1712

Description

A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper sanitization. When a DHCP client renews an existing lease with a malicious hostname, arbitrary commands can be executed with root privileges.

References