CVE-2025-44084
moderateUnauthenticated Command Injection in D-Link DI-8100 Router Firmware
CVE-2025-44084 is an unauthenticated command injection flaw (CWE-77) in D-Link DI-8100 router firmware, with build 16.07.26A1 identified as vulnerable; the CPE tagging also references the DI-8100G, so defenders should treat both model references as affected. The flaw is triggered by specially crafted HTTP requests sent to the device's web management interface, and per the CVSS vector (AV:N/PR:N) no authentication or user interaction is required. A successful attacker gains the highest-privilege shell on the firmware system, giving full control of the router. Any operator running the affected firmware is exposed, especially where the router's management interface is reachable from the WAN or the internet. As of now there is no public proof-of-concept and the issue is not in CISA KEV, but EPSS places it in the 97th percentile with a 20.1% probability of exploitation within 30 days, so near-term exploitation is considered likely even though no confirmed in-the-wild activity is reported.
What to do: Check D-Link's advisories for a firmware release superseding 16.07.26A1 and upgrade, since no fixed build is specified in the available data. Until patched, disable or restrict WAN-side web management so the router's HTTP interface is reachable only from trusted LAN networks. Given the unauthenticated, network-facing nature and high EPSS, prioritize internet-exposed units and review them for unexpected processes or configuration changes that would indicate compromise.
| D-Link DI-8100 firmware (CPE also tags DI-8100G firmware) | 16.07.26A1 (the only build explicitly identified as vulnerable; no other confirmed ranges provided) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.
- Vendors
- dlink
- Products
- di-8100g firmware
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.