← back
CVE-2025-63932

CVE-2025-63932

CVSS 7.3 HIGHEPSS 6.4%CWE-78
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.3EPSS 6.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Nov 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided by cgibin does not filter the HTTP SOAPAction header field. The unauthenticated remote attacker can execute the shell command.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →