CVE-2025-7836

MEDIUM

D-Link DIR-816L <2.06B01 - Command Injection

Title source: llm
STIX 2.1

Description

A vulnerability has been found in D-Link DIR-816L up to 2.06B01 and classified as critical. Affected by this vulnerability is the function lxmldbc_system of the file /htdocs/cgibin of the component Environment Variable Handler. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.316939
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.316939
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.617359
Product product
https://www.dlink.com/

Scores

CVSS v3 6.3
EPSS 0.0225
EPSS Percentile 84.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-74 CWE-77
Status published
Products (1)
dlink/dir-816l_firmware < 2.06b01
Published Jul 19, 2025
Tracked Since Feb 18, 2026