A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
History

Thu, 04 Sep 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dir-852
Dlink dir-852 Firmware
CPEs cpe:2.3:h:dlink:dir-852:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-852_firmware:1.00cn_b09:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dir-852
Dlink dir-852 Firmware

Tue, 02 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Sep 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dir-852
Vendors & Products D-link
D-link dir-852

Mon, 01 Sep 2025 00:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Title D-Link DIR-852 SOAP Service soap.cgi soapcgi_main os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-09-02T15:12:20.656Z

Reserved: 2025-08-31T08:18:37.778Z

Link: CVE-2025-9752

cve-icon Vulnrichment

Updated: 2025-09-02T14:34:26.343Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-01T01:15:46.817

Modified: 2025-09-04T18:47:25.440

Link: CVE-2025-9752

cve-icon Redhat

No data.