Sploitus

CVE-2025-55583

No indexed exploits for CVE-2025-55583 yet

D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitization or authentication. Remote attackers can exploit this to execute arbitrary commands as root via crafted HTTP requests.

Affected products
D-Link Dir-868L
Dlink dir-868l Firmware
= 2.05b02
CVSS 3.1
9.8 CRITICAL
EPSS
5.8% (92th percentile)
Weakness
CWE-306, CWE-668, CWE-78
NVD status
Analyzed
Published
2025-08-28
CVE-2025-55583 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-55583 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-55583 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.