CVE-2025-60854: D-Link r15 Firmware
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.
Affected products
- D-Link r15 Firmware: up to and including 1.20.01
Published 2025-12-02. Last modified 2026-06-17.