CVE-2025-1877

MEDIUM

D-Link DAP-1562 1.10 - Null Pointer Dereference

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_auth_check of the component HTTP POST Request Handler. The manipulation of the argument a1 leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

References (5)

Core 5
Core References
Permissions Required vdb-entry technical-description
https://vuldb.com/?id.298191
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.298191
Third Party Advisory third-party-advisory
https://vuldb.com/?submit.506526
Product product
https://www.dlink.com/

Scores

CVSS v3 6.5
EPSS 0.0096
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-476 CWE-404
Status published
Products (1)
dlink/dap-1562_firmware 1.10
Published Mar 03, 2025
Tracked Since Feb 18, 2026