rootpwn

critical · CVSS v3 8.8

CVE-2025-51457

D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at …

Description

D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint. An attacker with authenticated access can exploit some parameters to execute arbitrary system commands.

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
—
EPSS
—

← All CVEs