Impact
The flaw resides in the sub_456CF4 function of the component accessed via /boafrm/formSysCmd. A manipulated sysCmd argument allows an attacker to inject arbitrary operating‑system commands; the injected input is directly concatenated into a shell command without proper validation. This enables code execution, which could compromise the router’s confidentiality, integrity, and availability. The weakness is classified as command injection (CWE‑74) and OS command injection (CWE‑77).
Affected Systems
The vulnerability affects the D‑Link DIR‑825M router running firmware 1.1.8. No other affected versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack requires remote access to the router’s management interface, and the exploit has been made public, making it likely that attackers with network access could attempt exploitation.
OpenCVE Enrichment