CVE-2025-60854
CRITICALD-Link R15 (AX1500) <1.20.01 - Command Injection
Title source: llmDescription
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0016
EPSS Percentile
37.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-77
Status
published
Products (1)
dlink/r15_firmware
< 1.20.01
Published
Dec 02, 2025
Tracked Since
Feb 18, 2026