HIGH 8.8 NVD
CVE-2025-51457
D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint. An attacker wit
D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint. An attacker with authenticated access can exploit some parameters to execute arbitrary system commands.
References
- https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10428
- https://www.dlink.com/en/security-bulletin/
- https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10428
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-09-25 via NVD.
vulnfeed aggregates 11443 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.