CVE-2025-10440

medium

Description

A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1. Affected by this vulnerability is the function sub_4621DC of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument hname leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

References

https://www.dlink.com/

https://vuldb.com/?submit.647835

https://vuldb.com/?id.323874

https://vuldb.com/?ctiid.323874

https://github.com/2664521593/mycve/blob/main/D-Link/D-Link_CJ_1.md#exp

https://github.com/2664521593/mycve/blob/main/D-Link/D-Link_CJ_1.md

Details

Source: Mitre, NVD

Published: 2025-09-15

Updated: 2026-04-29

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.1211