CVE-2025-60344
🟠 Łataj w tym tygodniu
Luka przejścia ścieżki w routerach D-Link DSR umożliwia dostęp do plików poza zamierzonym katalogiem.
CVSS
8.6
EPSS
10.9%
Exploit
none
Vendor
Opis źródłowy (NVD)
A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as “../”). Successful exploitation may allow access to files outside of the intended directory, potentially exposing sensitive system or configuration files. The issue results from insufficient validation or sanitization of user-supplied input. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.
path-traversal
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.6 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 10.9% |
| Opublikowano (NVD) | 2025-10-21 15:15:39 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 11:10:00 UTC |