CVE-2025-55583
Description
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitization or authentication. Remote attackers can exploit this to execute arbitrary commands as root via crafted HTTP requests.
In plain language
AI Act nowThis is a serious remote “command execution” bug in certain D-Link router firmware, meaning an attacker on the internet could potentially run commands on your router without logging in. If your business uses one of the listed models and it’s running the vulnerable firmware, you should act now by isolating it from the internet and upgrading.
CVE-2025-55583 is an unauthenticated OS command injection in the D-Link DIR-868L B1 firmware’s fileaccess.cgi handling of HTTP uploads (/dws/api/UploadFile), where a request parameter (pre_api_arg) is passed to OS-level shell execution without sanitization, enabling remote attackers to execute commands as root.
What to do now
- Check the router model and current firmware version; treat FW2.05WWB02 on DIR-868L B1 as vulnerable.
- If you have one of the affected D-Link router models listed (DIR-868L family models), and it’s on the vulnerable firmware, plan to upgrade immediately to the latest D-Link firmware that remediates CVE-2025-55583.
- Until you can upgrade, block inbound access to the router from the internet (allow only your internal admin network/VPN paths) using firewall rules.
- After upgrading, re-check the firmware version to confirm it changed from FW2.05WWB02 to a fixed release and verify the router is no longer reachable from the internet for the affected upload endpoint.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-55583 and every CVE in our database. Create a free account — no credit card required.
Create Free Account