A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
History

Thu, 04 Sep 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink di-500wf
Dlink di-500wf Firmware
CPEs cpe:2.3:h:dlink:di-500wf:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-500wf_firmware:14.04.10a1t:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink di-500wf
Dlink di-500wf Firmware

Tue, 02 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link di-500wf
Vendors & Products D-link
D-link di-500wf

Sun, 31 Aug 2025 20:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Title D-Link DI-500WF jhttpd version_upgrade.asp os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-09-02T15:13:06.848Z

Reserved: 2025-08-30T16:53:09.696Z

Link: CVE-2025-9745

cve-icon Vulnrichment

Updated: 2025-09-02T14:36:36.436Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-31T21:15:30.983

Modified: 2025-09-04T16:47:38.047

Link: CVE-2025-9745

cve-icon Redhat

No data.