CVE Tools

CVE-2025-55583

No known exploitation. EPSS puts it in the 94th percentile. A vendor fix is available.

Published Updated Sources: CVE.org, NVD, BDU

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check the router model and current firmware version; treat FW2.05WWB02 on DIR-868L B1 as vulnerable.
  2. If you have one of the affected D-Link router models listed (DIR-868L family models), and it’s on the vulnerable firmware, plan to upgrade immediately to the latest D-Link firmware that remediates CVE-2025-55583.
  3. Until you can upgrade, block inbound access to the router from the internet (allow only your internal admin network/VPN paths) using firewall rules.
  4. After upgrading, re-check the firmware version to confirm it changed from FW2.05WWB02 to a fixed release and verify the router is no longer reachable from the internet for the affected upload endpoint.

What it is

From the CVE record

D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitization or authentication. Remote attackers can exploit this to execute arbitrary commands as root via crafted HTTP requests.

In plain language

Written by AI from the record

This is a serious remote “command execution” bug in certain D-Link router firmware, meaning an attacker on the internet could potentially run commands on your router without logging in. If your business uses one of the listed models and it’s running the vulnerable firmware, you should act now by isolating it from the internet and upgrading.

CVE-2025-55583 is an unauthenticated OS command injection in the D-Link DIR-868L B1 firmware’s fileaccess.cgi handling of HTTP uploads (/dws/api/UploadFile), where a request parameter (pre_api_arg) is passed to OS-level shell execution without sanitization, enabling remote attackers to execute commands as root.

If you're affected

  • Router fully compromised
  • Network disruption and downtime
  • Malware persistence on network
  • Traffic interception or spying

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS94th
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

7.0% chance of exploitation activity in the next 30 days, which ranks it in the 94th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

5 events over 12 days, from the signal feeds we watch.

  1. Patch availablerecord updated
  2. Publishedweakness classified, att&ck mapped

Affected products

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Scored 9.8 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Dir-868l Firmware, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store