Sploitus

CVE-2025-60675

No indexed exploits for CVE-2025-60675 yet

A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /tmp/new_qos.rule configuration file. The vulnerability occurs because parsed fields from the configuration file are concatenated into command strings and executed via system() without any sanitization. An attacker with write access to /tmp/new_qos.rule can execute arbitrary commands on the device.

Affected products
Dir-823
Dlink dir-823g Firmware
= 1.0.2b05_20181207
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
1.5% (72th percentile)
Weakness
CWE-77
NVD status
Modified
Published
2025-11-13
CVE-2025-60675 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-60675 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-60675 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.