CVE-2025-51457

8.8

D-Link · DAP-2610

D-Link DAP-2610 devices contain an authenticated command injection vulnerability in the web interface that allows arbitrary system command execution.

Executive summary

An authenticated command injection vulnerability in D-Link DAP-2610 devices poses a high risk of complete system compromise via arbitrary command execution.

Vulnerability

This vulnerability is a command injection flaw located within the /index.xgi endpoint of the web interface. It requires an attacker to have authenticated access to the device to successfully execute system-level commands.

Business impact

The ability to execute arbitrary system commands allows an attacker to gain full control over the affected network device. Given the CVSS score of 8.8, this vulnerability represents a high-severity risk that could lead to unauthorized data access, persistence within the network, or potential lateral movement into internal systems.

Remediation

Immediate Action: Review the official D-Link security bulletin at the provided support URL and apply all available security updates or configuration changes recommended by the vendor.

Proactive Monitoring: Monitor device access logs for unusual administrative activity and inspect the /index.xgi endpoint for suspicious request patterns or unexpected parameters.

Compensating Controls: Restrict access to the web management interface to trusted management IP addresses only, and employ a network-based firewall to block unauthorized access to the device management port.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the D-Link DAP-2610 should prioritize checking for firmware updates via the official D-Link security portal. Because command injection flaws often lead to full administrative compromise, restricting management interface access is a necessary interim step to mitigate the risk of exploitation by malicious actors.

More D-Link CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources