Junglewise Threat Intelligence

CVE-2025-60673: D-Link DIR-878 A1 command injection in SetDMZSettings

CVE-2025-60673 · Severity: medium · CVSS 6.5 · Published 2025-11-13

Technologies: Dlink Dir-878, Dlink Dir-878 Firmware. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability exists in the D-Link DIR-878 A1 router, a device used to provide wireless internet connectivity for homes and small offices. An attacker can exploit this flaw to take control of the router without needing a password or physical access. This could allow an unauthorized user to disrupt internet service, intercept network traffic, or use the device as a foothold for further attacks on the local network.

Technical details

An unauthenticated command injection vulnerability exists in the 'SetDMZSettings' functionality of the D-Link DIR-878 A1 router (firmware FW101B04.bin). The vulnerability stems from improper sanitization of the 'IPAddress' parameter in prog.cgi, which is stored in NVRAM as 'dmz_ipaddr'. This value is subsequently retrieved by librcm.so and used to construct iptables shell commands via snprintf() before being executed by twsystem(). A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request containing shell metacharacters in the IPAddress field, leading to arbitrary code execution with elevated privileges.

Affected products

  • D-Link DIR-878 A1 FW101B04.bin

Timeline

  • 2025-11-13: disclosed
  • 2025-11-13: advisory

References

Related threats