CVE Tools

CVE-2018-25115

D-Link DIR-110/412/600/615/645/815 RCE via service.cgi

Published: Aug 27, 2025Updated: Sep 24, 2025 Sources: CVE List NVD BDUCWE-78

Description

Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication. The flaw stems from improper input handling in the EVENT=CHECKFW parameter, which is passed directly to the system shell without sanitization. A crafted HTTP POST request can inject commands that are executed with root privileges, resulting in full device compromise. These router models are no longer supported at the time of assignment and affected version ranges may vary. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-08-21 UTC.

In plain language

AI Worth attention

This is a serious “send a bad web request to your router” flaw that lets an attacker take full control of certain D-Link DIR routers over the internet—if your business still uses affected DIR-110/412/600/615/645/815 (and DIR-110/DIR-412/DIR-600 firmware) and the router is reachable online, you should act now.

Executive summary

Unauthenticated remote command execution via the D-Link router’s service.cgi endpoint (EVENT=CHECKFW handling) allows an attacker to inject commands that execute with root privileges when the device is reachable over the network.

If affected, business impact
Full router takeoverTraffic interception or redirectionDevice settings manipulationDisruption of network operations

What to do now

  1. Check whether you run any of these D-Link router models: dir-645, dir-600, dir-110, dir-412, dir-610, dir-615, dir-815 (including dir-110 firmware, dir-412 firmware, dir-600 firmware) and confirm the router is running a vulnerable firmware version.
  2. If you are unsure or can’t verify quickly, treat it as affected: assume service.cgi is reachable and that an attacker on the network could reach it.
  3. Remove internet exposure to the router’s web/maintenance services (apply firewall rules so the router can’t be reached from the public internet).
  4. Update/replace the router with a safe, supported model/firmware that is not vulnerable; if your device is out of support, plan a replacement as the permanent fix.
  5. After changes, verify that the router is no longer reachable from outside your network (for example, only admin access from your office IP/VPN is allowed).
Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 6 more affected products View all →

Exploitability

2 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Execution
View detailed technique mapping

References

and 2 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2018-25115 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store