CVE-2025-55583
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitization or authentication. Remote attackers can exploit this to execute arbitrary commands as root via crafted HTTP requests.
- Affected products
- D-Link Dir-868L
- Dlink dir-868l Firmware
- = 2.05b02
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 5.8% (92th percentile)
- Weakness
- CWE-306, CWE-668, CWE-78
- NVD status
- Analyzed
- Published
- 2025-08-28
CVE-2025-55583 at NVD
No indexed exploits for CVE-2025-55583 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-55583 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.