Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21746 | An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlying Linux operating system. Successful exploitation enables full system compromise. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 21 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dsp-w215 Firmware |
|
| CPEs | cpe:2.3:o:dlink:dsp-w215_firmware:1.05:b01:*:*:*:*:*:* | |
| Vendors & Products |
Dlink
Dlink dsp-w215 Firmware |
Thu, 17 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Jul 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlying Linux operating system. Successful exploitation enables full system compromise. | |
| Title | D-Link DSP-W110A1 Cookie Command Injection | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-21T19:15:26.371Z
Reserved: 2025-04-15T19:15:22.561Z
Link: CVE-2025-34125
Updated: 2025-07-17T19:29:22.382Z
Status : Awaiting Analysis
Published: 2025-07-16T22:15:24.003
Modified: 2025-07-17T21:15:50.197
Link: CVE-2025-34125
No data.
OpenCVE Enrichment
No data.
EUVD