CVE-2025-55583 describes an unauthenticated OS command injection vulnerability in the D-Link DIR-868L B1 router firmware version FW2.05WWB02. Specifically, the /dws/api/UploadFile endpoint within the fileaccess.cgi component allows remote attackers to execute arbitrary commands as root by injecting malicious input into the pre_api_arg parameter without prior authentication. This critical vulnerability, rated 9.8 CVSS, carries a high potential for complete compromise of confidentiality, integrity, and availability due to its network-based attack vector and low attack complexity. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the severe nature of the flaw warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.05b02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-868l_firmware:2.05b02:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.