Impact
An issue in D-Link DIR-1253 routers running firmware version 1.0.1.250923.142435 allows an attacker to modify the /etc/shadow component file and gain higher privileges. The flaw permits elevation of a non-privileged user to administrative rights, enabling full control over the device and potentially the surrounding network.
Affected Systems
The vulnerability impacts the D-Link DIR-1253 model with firmware 1.0.1.250923.142435. No other models or firmware revisions are noted as affected.
Risk and Exploitability
The CVSS score of 9.8 reflects a critical severity, while the EPSS score of <1% suggests a low probability of exploitation in the immediate future. The flaw is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attacker may target the vulnerable /etc/shadow component through remote access such as the router's web interface or via local code that can reach the component, allowing a non-privileged user to obtain full administrative control.
OpenCVE Enrichment