CVE-2025-25893: D-Link DSL-3782 Firmware

High severity, CVSS 8.0. EPSS: 1% chance of exploitation in the next 30 days.

An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.

Affected products

  • D-Link DSL-3782 Firmware: version 1.01 only

Published 2025-02-18. Last modified 2026-06-17.