CVE-2025-9752
7.3D-Link · DIR-852
A remote OS command injection vulnerability exists in the D-Link DIR-852 router via the soapcgi_main function in soap.cgi.
Executive summary
A remote OS command injection vulnerability in the D-Link DIR-852 router poses a significant risk to network security as it allows unauthenticated attackers to execute arbitrary commands.
Vulnerability
The vulnerability is an OS command injection flaw (CWE-78) located within the soapcgi_main function of the soap.cgi component. It can be triggered by an unauthenticated remote attacker through the manipulation of the service argument.
Business impact
Successful exploitation allows an attacker to execute arbitrary commands on the affected device, potentially leading to full device compromise or lateral movement within the internal network. With a CVSS score of 7.3, this high-severity vulnerability represents a significant risk, particularly because the device is confirmed to be end-of-life and no longer receives vendor security support.
Remediation
Immediate Action: Given that this device is no longer supported by the vendor, the most effective remediation is to retire and replace the hardware with a currently supported model.
Proactive Monitoring: Monitor network traffic for anomalous SOAP requests or suspicious shell execution patterns directed at the device IP address.
Compensating Controls: Isolate the affected device in a restricted network segment or implement strict ingress filtering at the perimeter firewall to block unauthorized access to the SOAP service interface.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up provided via the GitHub reference in the enrichment data.
Analyst recommendation
The severity of this command injection vulnerability, combined with the lack of vendor support for the DIR-852, necessitates immediate action. Organizations should prioritize the decommissioning of this hardware to eliminate the risk, as no official patches are expected to be released for this legacy device.
More D-Link CVEs
Sources
Originally found and disclosed by iC0rner (VulDB User), per the CVE Program record.
- VDB-322053 | D-Link DIR-852 SOAP Service soap.cgi soapcgi_main os command injection Vulnerability database entry
- VDB-322053 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #640590 | D-Link DIR-852 1.00CN B09 Command Injection Third-party advisory
- Exploit / PoC
- dlink.com