CVE-2025-29165
Received
Received - Intake
Privilege Escalation in D-Link DIR-1253 via etc/shadow.sample
Publication date: 2026-03-05
Last updated on: 2026-05-06
Assigner: MITRE
Description
Description
An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dlink | dir-1253_firmware | 1.6.1684 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |