CVE-2025-9387 | DCN DCME-720 9.1.5.11 Web Management Backend ip_block.php ip os command injection
A vulnerability has been found in DCN DCME-720 9.1.5.11 and classified as critical. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block.php of the component Web Management Backend. Performing manipulation of the argument ip results in os command injection.
This vulnerability is cataloged as CVE-2025-9387. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Other products might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.