CVE-2025-5620 | D-Link DIR-816 1.10CNB05 /goform/setipsec_config localIP/remoteIP os command injection (EUVD-2025-16943)
A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsec_config of the file /goform/setipsec_config. The manipulation of the argument localIP/remoteIP leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2025-5620. It is possible to launch the attack remotely. Furthermore, there is an exploit available.