CVE-2018-25115
D-Link DIR-110/412/600/615/645/815 RCE via service.cgi
Description
Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication. The flaw stems from improper input handling in the EVENT=CHECKFW parameter, which is passed directly to the system shell without sanitization. A crafted HTTP POST request can inject commands that are executed with root privileges, resulting in full device compromise. These router models are no longer supported at the time of assignment and affected version ranges may vary. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-08-21 UTC.
In plain language
AI Worth attentionThis is a serious “send a bad web request to your router” flaw that lets an attacker take full control of certain D-Link DIR routers over the internet—if your business still uses affected DIR-110/412/600/615/645/815 (and DIR-110/DIR-412/DIR-600 firmware) and the router is reachable online, you should act now.
Unauthenticated remote command execution via the D-Link router’s service.cgi endpoint (EVENT=CHECKFW handling) allows an attacker to inject commands that execute with root privileges when the device is reachable over the network.
What to do now
- Check whether you run any of these D-Link router models: dir-645, dir-600, dir-110, dir-412, dir-610, dir-615, dir-815 (including dir-110 firmware, dir-412 firmware, dir-600 firmware) and confirm the router is running a vulnerable firmware version.
- If you are unsure or can’t verify quickly, treat it as affected: assume service.cgi is reachable and that an attacker on the network could reach it.
- Remove internet exposure to the router’s web/maintenance services (apply firewall rules so the router can’t be reached from the public internet).
- Update/replace the router with a safe, supported model/firmware that is not vulnerable; if your device is out of support, plan a replacement as the permanent fix.
- After changes, verify that the router is no longer reachable from outside your network (for example, only admin access from your office IP/VPN is allowed).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-25115 and every CVE in our database. Create a free account — no credit card required.
Create Free Account