CVE-2025-60344
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-21

Last updated on: 2026-02-27

Assigner: MITRE

Description
A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as β€œ../”). Successful exploitation may allow access to files outside of the intended directory, potentially exposing sensitive system or configuration files. The issue results from insufficient validation or sanitization of user-supplied input. Affected Products include: DSR-150, DSR-150N, and DSR-250N v1.09B32_WW.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-21
Last Modified
2026-02-27
Generated
2026-05-07
AI Q&A
2025-10-21
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
d-link dsr-150 *
d-link dsr-250n *
d-link dsr-150n *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-24 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an unauthenticated Local File Inclusion (LFI) issue in certain D-Link DSR series routers. It allows remote attackers to access and retrieve sensitive configuration files in clear text without needing to log in. These files include administrative credentials, VPN settings, and other sensitive data.


How can this vulnerability impact me? :

The vulnerability can lead to full administrative access to the affected router by exposing sensitive configuration files. This means an attacker could control the router, potentially intercept network traffic, change settings, or disrupt network operations.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart