ZeroHour

CVE-2025-4341

moderate

Command Injection in D-Link DIR-880L Router Firmware (ssdpcgi)

CVSS 4.0
5.3 medium
EPSS
21%p97
Published
()
Modified
AI analysis

D-Link DIR-880L firmware up to and including 104WWb01 contains a command injection vulnerability (CWE-74/CWE-77) in the request-header handler of the ssdpcgi component, specifically function sub_16570 in /htdocs/ssdpcgi. An attacker triggers it by sending manipulated values in the HTTP_ST, REMOTE_ADDR, REMOTE_PORT or SERVER_ID arguments processed by that component. Successful exploitation allows a remote attacker to inject and execute arbitrary commands on the router. Only the DIR-880L is affected, and the model is end-of-life, so it no longer receives vendor support or fixes. An exploit has been publicly disclosed and may be used; the issue is not in CISA KEV, carries a CVSS 4.0 base score of 5.3, and EPSS estimates roughly a 21% probability of exploitation within 30 days (97th percentile).

What to do: D-Link no longer supports the DIR-880L, so a patched firmware may never be released; confirm your unit's firmware version (everything up to 104WWb01 is affected) and treat the device as vulnerable. As a mitigation, restrict access to the router's web/ssdpcgi-facing interface (for example by disabling UPnP and avoiding WAN-side management exposure) and plan replacement with a currently supported model. Monitor D-Link's support pages in case an end-of-life firmware update is issued.

Affected
D-Link DIR-880L firmwareall versions up to and including 104WWb01 (end-of-life product, no longer supported by the maintainer; no fixed release indicated in the available data)
Estimated exposure
moderatelikely on the order of tens of thousands of devices still in service (single discontinued consumer router model) — No authoritative install-base figure or internet-exposure scan count exists for this specific end-of-life model, so the estimate extrapolates from the DIR-880L's multi-year retail run and the typical long service life of consumer routers,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. Affected by this vulnerability is the function sub_16570 of the file /htdocs/ssdpcgi of the component Request Header Handler. The manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVER_ID leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

Vendors
dlink
Products
dir-880l firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.