Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-60344

Опубликовано: 21 окт. 2025
Источник: nvd
CVSS3: 8.6
CVSS3: 6.6
EPSS Средний

Описание

A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as “../”). Successful exploitation may allow access to files outside of the intended directory, potentially exposing sensitive system or configuration files. The issue results from insufficient validation or sanitization of user-supplied input. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.

EPSS

Процентиль: 95%
0.10268
Средний

8.6 High

CVSS3

6.6 Medium

CVSS3

Дефекты

CWE-24
CWE-200

Связанные уязвимости

CVSS3: 6.6
github
10 месяцев назад

An unauthenticated Local File Inclusion (LFI) vulnerability in D-Link DSR series routers allows remote attackers to retrieve sensitive configuration files in clear text. The exposed files contain administrative credentials, VPN settings, and other sensitive information, enabling full administrative access to the router. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.

CVSS3: 10
fstec
10 месяцев назад

Уязвимость компонента Setting Handler микропрограммного обеспечения маршрутизаторов D-Link DSR-150, DSR-150N и DSR-250, позволяющая нарушителю получить полный доступ к устройствам

EPSS

Процентиль: 95%
0.10268
Средний

8.6 High

CVSS3

6.6 Medium

CVSS3

Дефекты

CWE-24
CWE-200