D-Link DIR-890L and DIR-806A1 Command Injection Vulnerability

Vulnerability

A critical command injection vulnerability has been identified in the D-Link DIR-890L and DIR-806A1 routers, specifically in versions through DIR-890L 108B03 and DIR-806A1 100CNb11. The vulnerability resides in the '/htdocs/soap.cgi' file, within the 'sub_175C8' function. This issue allows remote attackers to inject commands, potentially leading to arbitrary code execution. The vulnerability affects products that are no longer supported by the manufacturer.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected router.

Reproduction

To reproduce this vulnerability, send a request to the router's SOAP CGI interface, specifically targeting the 'sub_175C8' function. Inject commands through the request header to achieve remote command execution. This can be done by crafting a payload that exploits the command injection flaw and sending it to the router's port 49152.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
6.2
remediation
0.0
relevance
0.0
threat
6.5
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.