CVE-2025-9026 is a critical OS command injection vulnerability affecting D-Link DIR-860L 2.04.B04 routers, specifically within the Simple Service Discovery Protocol component. This flaw allows unauthenticated, remote attackers to execute arbitrary commands with high impact on confidentiality, integrity, and availability, as reflected by its CVSS score of 9.8. While there is no evidence of active exploitation in the wild, the exploit has been publicly disclosed, and the vulnerability affects end-of-life products, increasing the risk of unpatched systems being targeted. The high number of community mentions indicates significant interest in this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.04.b04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-860l_firmware:2.04.b04:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.