CVE-2025-34125
CRITICALD-Link DSP-W110A1 <1.05B01 - Command Injection
Title source: llmDescription
An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlying Linux operating system. Successful exploitation enables full system compromise.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotehardware
https://www.exploit-db.com/exploits/37628
metasploit
WORKING POC
NORMAL
rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/dlink_dspw110_cookie_noauth_exec.rb
Scores
CVSS v4
9.3
EPSS
0.4937
EPSS Percentile
97.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Details
CWE
CWE-78
Status
published
Products (1)
D-Link/DSP-W110A1
1.05B01
Published
Jul 16, 2025
Tracked Since
Feb 18, 2026