CVE-2025-8956
A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
- Affected products
- D-Link Dir-818Lw
- Dlink dir-818l Firmware
- = 105b01
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 18.1% (97th percentile)
- Weakness
- CWE-74, CWE-77
- NVD status
- Analyzed
- Published
- 2025-08-14
CVE-2025-8956 at NVD
No indexed exploits for CVE-2025-8956 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-8956 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.