SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-44084

D-link DI-8100 16.07.26A1 is vulnerable to Command Injection.

CRITICAL 9.8EPSS 20.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 20.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
20.08% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-77
Affected
dlink/di-8100g firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.