CVE-2025-11488
7.3D-Link · DIR-852
A command injection vulnerability in the D-Link DIR-852 router allows remote attackers to execute arbitrary commands via the /HNAP1/ endpoint.
Executive summary
A critical command injection vulnerability in D-Link DIR-852 routers allows unauthenticated remote attackers to execute arbitrary code, posing a significant risk of full system compromise.
Vulnerability
This vulnerability is a command injection flaw (CWE-77) located in the /HNAP1/ directory of the affected firmware. It allows unauthenticated remote attackers to inject and execute arbitrary system commands.
Business impact
Successful exploitation of this vulnerability grants an attacker remote code execution capabilities on the device. This can lead to complete loss of confidentiality, integrity, and availability of the router, potentially enabling further lateral movement within the local network. Given the CVSS score of 7.3, this represents a significant security risk for environments still utilizing this end-of-life hardware.
Remediation
Immediate Action: Since the product is no longer supported by the manufacturer, the immediate action is to decommission and replace the affected D-Link DIR-852 hardware.
Proactive Monitoring: Monitor network traffic for suspicious activity directed at the /HNAP1/ endpoint and review device logs for unauthorized command execution patterns.
Compensating Controls: If immediate replacement is not feasible, isolate the device behind a robust firewall and restrict access to the management interface to trusted internal segments only.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the technical write-up referenced by the CVE record.
Analyst recommendation
The D-Link DIR-852 is an end-of-life product and is no longer receiving security updates from the vendor. Organizations currently utilizing this device are at extreme risk of compromise due to the public availability of exploit details. It is strongly recommended to retire this hardware immediately and transition to a supported networking solution to ensure ongoing network security and integrity.
More D-Link CVEs
Sources
Originally found and disclosed by sheratan (VulDB User), per the CVE Program record.
- VDB-327605 | D-Link DIR-852 HNAP1 command injection Vulnerability database entry
- VDB-327605 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #667505 | D-Link DIR-852 A1 Command Injection Third-party advisory
- Exploit / PoC
- dlink.com