{"id":"CVE-2025-51457","published":"2026-09-25T13:17:05.613","lastModified":"2026-09-25T16:17:23.823","description":"D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint. An attacker with authenticated access can exploit some parameters to execute arbitrary system commands.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-77"],"vendors":[],"products":[],"references":[{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10428","tags":[]},{"url":"https://www.dlink.com/en/security-bulletin/","tags":[]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10428","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows an authenticated attacker to inject arbitrary commands via the /index.xgi endpoint, leading to potential remote code execution.","exploitability":"Exploitation requires authenticated access and specific parameter manipulation, making it moderately difficult.","blast_radius":"If exploited, the vulnerability could lead to full control over the device, including data exfiltration and denial of service.","remediation":"Upgrade to D-Link DAP-2610 version 2.06B08r099 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","web","command-injection"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:05:42.669Z"}}