CVE-2025-22968

CRITICAL

Dlink Dwr-m972v Firmware - Code Injection

Title source: rule

Description

An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions

Exploits (2)

nomisec WRITEUP 6 stars
by CRUNZEX · poc
https://github.com/CRUNZEX/CVE-2025-22968
github WRITEUP 1 stars
by AsimCr · pythonpoc
https://github.com/AsimCr/POC_Collecter_Bot/tree/master/CVE_Looter/CVE_Archive/CVE-2025-22968

Scores

CVSS v3 9.8
EPSS 0.4206
EPSS Percentile 97.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
dlink/dwr-m972v_firmware 1.05ssg
Published Jan 15, 2025
Tracked Since Feb 18, 2026