Metrics
Affected Vendors & Products
Fri, 29 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 28 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 28 Aug 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dlink
Dlink dcs-825l |
|
Vendors & Products |
Dlink
Dlink dcs-825l |
Wed, 27 Aug 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-269 CWE-494 |
|
Metrics |
cvssV3_1
|
Wed, 27 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries such as `dcp` and `signalc` without verifying integrity, authenticity, or permissions. An attacker with local filesystem access (via physical access, firmware modification, or debug interfaces) can replace these binaries with malicious payloads. The script executes these binaries as root in an infinite loop, leading to persistent privilege escalation and arbitrary code execution. This issue is mitigated in v1.09.02, but the product is officially End-of-Life and unsupported. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-27T00:00:00.000Z
Updated: 2025-08-29T13:50:44.360Z
Reserved: 2025-08-13T00:00:00.000Z
Link: CVE-2025-55582

Updated: 2025-08-27T20:33:10.453Z

Status : Awaiting Analysis
Published: 2025-08-27T20:15:33.113
Modified: 2025-08-29T16:24:09.860
Link: CVE-2025-55582

No data.