An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlying Linux operating system. Successful exploitation enables full system compromise.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Jul 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlying Linux operating system. Successful exploitation enables full system compromise. | |
Title | D-Link DSP-W110A1 Cookie Command Injection | |
Weaknesses | CWE-78 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-16T21:09:59.215Z
Updated: 2025-07-17T19:29:26.115Z
Reserved: 2025-04-15T19:15:22.561Z
Link: CVE-2025-34125

Updated: 2025-07-17T19:29:22.382Z

Status : Awaiting Analysis
Published: 2025-07-16T22:15:24.003
Modified: 2025-07-17T21:15:50.197
Link: CVE-2025-34125

No data.