Impact
An unauthenticated command injection flaw in the cookie handling of the lighttpd web server on the D-Link DSP-W110A1 firmware allows attackers to send specially crafted cookie values that are processed unchecked. This vulnerability enables remote attackers to execute arbitrary commands on the underlying Linux operating system, resulting in full system compromise.
Affected Systems
The affected device is the D-Link DSP-W110A1 router with firmware version 1.05B01. Users deploying this version should verify the build and apply an updated firmware that removes the vulnerability.
Risk and Exploitability
The flaw scores 9.3 on the CVSS scale, with an EPSS score of 75%, indicating a high likelihood of exploitation. Although it is not yet listed in the CISA KEV catalog, the combination of unauthenticated access and remote code execution makes it a top priority to patch. Attackers can exploit the vulnerability over the network without any credentials by sending a crafted request to the web interface, which processes the malicious cookie and executes the command.
OpenCVE Enrichment
EUVD