Vulnerability Description
A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of the component alphapd. Executing manipulation of the argument AdminID can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dcs-930L Firmware | 1.15.04 |
| Dlink | Dcs-930L | - |
Related Weaknesses (CWE)
References
- https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/D-Link/vuln-1/D-Link%20VulneraExploitThird Party Advisory
- https://vuldb.com/?ctiid.334667Permissions RequiredVDB Entry
- https://vuldb.com/?id.334667Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.701774Third Party AdvisoryVDB Entry
- https://www.dlink.com/Product
FAQ
What is CVE-2025-14225?
CVE-2025-14225 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of the component alphapd. Executing manipulation of the argument AdminID can lead to...
How severe is CVE-2025-14225?
CVE-2025-14225 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-14225?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dcs-930L Firmware, Dlink Dcs-930L.