CVE-2025-9752
D-Link DIR-852 SOAP Service soap.cgi soapcgi_main os command injection
Vexday Risk Score
18Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 15.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
01 Sep 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
D-Link · DIR-852Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →