CVE-2025-9752

HIGH

D-Link DIR-852 1.00CN B09 - OS Command Injection via SOAP Service soapcgi_main Function

Title source: llm
STIX 2.1

Description

A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.322053
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.322053
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.640590
Exploit, Issue Tracking exploit issue-tracking
https://github.com/i-Corner/cve/issues/18
Product product
https://www.dlink.com/

Scores

CVSS v3 7.3
EPSS 0.0114
EPSS Percentile 78.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-77 CWE-78
Status published
Products (1)
dlink/dir-852_firmware 1.00cn_b09
Published Sep 01, 2025
Tracked Since Feb 18, 2026