CVE-2025-29516
7.2D-Link · DSL-7740C
D-Link DSL-7740C routers running firmware DSL7740C.V6.TR069.20211230 contain a command injection vulnerability in the backup function.
Executive summary
A critical command injection vulnerability in the D-Link DSL-7740C router allows authenticated attackers to execute arbitrary system commands, potentially leading to a total device compromise.
Vulnerability
The device contains a command injection flaw within its backup functionality. The CVSS vector (PR:H) indicates that an attacker must possess high privileges to successfully trigger this vulnerability.
Business impact
The ability to inject arbitrary commands into the router operating system poses a significant risk to network integrity. Successful exploitation could result in full administrative control over the device, enabling attackers to intercept traffic, pivot into internal network segments, or permanently disable the hardware. With a CVSS score of 7.2, this vulnerability represents a high risk to the availability and confidentiality of the affected network infrastructure.
Remediation
Immediate Action: Review the D-Link security bulletin for firmware updates and apply the latest available patch to address the command injection flaw.
Proactive Monitoring: Monitor device logs for unusual administrative activity or unexpected system processes initiated by the backup function.
Compensating Controls: Restrict administrative access to the device management interface to authorized IP addresses only and disable remote management features if they are not strictly required for operations.
Exploitation status
Public Exploit Available: Yes — a public proof-of-concept exists as documented in the referenced GitHub Gist.
Analyst recommendation
Given the high CVSS severity and the existence of a public proof-of-concept, administrators should treat this vulnerability with urgency. Ensure that administrative interfaces are secured and prioritize the application of vendor patches as soon as they become available to prevent unauthorized system execution.