CVE-2025-15245 is a path traversal vulnerability in the D-Link DCS-850L 1.02.09 firmware update service, specifically affecting the uploadfirmware function when manipulating the DownloadFile argument. This vulnerability, which impacts an unsupported product, has a low CVSS score of 3.3 due to its local network attack vector and limited impact (confidentiality only). While a public exploit exists, there is no evidence of active exploitation, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.02.09CPE matchmatch criteria | cpe:2.3:o:dlink:dcs-850l_firmware:1.02.09:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.