CVE-2025-4341 | D-Link DIR-880L up to 104WWb01 Request Header /htdocs/ssdpcgi sub_16570 HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVER_ID command injection
A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. Affected by this vulnerability is the function sub_16570 of the file /htdocs/ssdpcgi of the component Request Header Handler. The manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVER_ID leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2025-4341. The attack can be launched remotely. Furthermore, there is an exploit available.