A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
History

Mon, 01 Sep 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dir-852
Vendors & Products D-link
D-link dir-852

Mon, 01 Sep 2025 00:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Title D-Link DIR-852 SOAP Service soap.cgi soapcgi_main os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-09-01T00:02:06.532Z

Updated: 2025-09-01T00:02:06.532Z

Reserved: 2025-08-31T08:18:37.778Z

Link: CVE-2025-9752

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-01T01:15:46.817

Modified: 2025-09-01T01:15:46.817

Link: CVE-2025-9752

cve-icon Redhat

No data.