CVE-2024-57595
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request.
Published 2025-01-27. Last modified 2026-06-17.