← Back

CVE-2025-60675

nvd nist
Published: Nov 13, 2025Modified: Jul 5, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /tmp/new_qos.rule configuration file. The vulnerability occurs because parsed fields from the configuration file are concatenated into command strings and executed via system() without any sanitization. An attacker with write access to /tmp/new_qos.rule can execute arbitrary commands on the device.

Affected (1)

1 product
Dir 823g Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.2b05_20181207
Running on/withPlatform Versions
Dlink
Dir 823g
All versions

References (3)

Source: cve@mitre.org
Product
Source: cve@mitre.org
Vendor Advisory

Timeline

No history available yet.