CVE-2025-10689

MEDIUM

D-Link DIR-645 105B01 - OS Command Injection via soapcgi_main Service Argument

Title source: llm
STIX 2.1

Description

A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the argument service leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.324813
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.324813
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.653689
Product product
https://www.dlink.com/

Scores

CVSS v3 6.3
EPSS 0.0023
EPSS Percentile 45.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-77
Status published
Products (1)
dlink/dir-645_firmware 1.05b01
Published Sep 18, 2025
Tracked Since Feb 18, 2026