CVE-2025-13562

7.3

D-Link · DIR-852

A command injection vulnerability in the D-Link DIR-852 gena.cgi endpoint allows unauthenticated remote attackers to execute arbitrary system commands with root privileges.

Executive summary

An unauthenticated command injection vulnerability in D-Link DIR-852 routers poses a critical risk of full system compromise for affected devices.

Vulnerability

This vulnerability is a command injection (CWE-77) flaw located in the gena.cgi script. An unauthenticated attacker can trigger this by sending a crafted HTTP SUBSCRIBE request with a malicious service argument to the target device.

Business impact

Successful exploitation grants an attacker arbitrary command execution with root privileges on the router. Given the device's role as a network gateway, this could lead to complete interception of network traffic, unauthorized access to internal resources, or the use of the device in botnet activities. While the CVSS score is 7.3, the potential for full system control and the absence of a vendor-provided patch make this a significant security risk.

Remediation

Immediate Action: As this product is no longer supported by the vendor, there is no patch available. Administrators should immediately decommission these devices and replace them with currently supported hardware.

Proactive Monitoring: Monitor network traffic for unexpected SUBSCRIBE requests directed at the gena.cgi endpoint or unusual telnet activity originating from the device.

Compensating Controls: If immediate replacement is not possible, isolate the device behind a robust firewall and restrict access to the web management interface, particularly from untrusted or external networks.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists via the researcher write-up at the referenced GitHub repository.

Analyst recommendation

Due to the end-of-life status of the D-Link DIR-852 and the availability of functional exploit code, the risk of compromise is high. We strongly recommend that all organizations identify and remove these units from their network infrastructure immediately to prevent potential unauthorized access and lateral movement.

More D-Link CVEs

Sources

Originally found and disclosed by XU17 (VulDB User), per the CVE Program record.