AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-34125

UNKNOWN · CVSS N/A EPSS 3.13% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-07-16 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. It affects Linux. Public exploit code or proof-of-concept references have been detected in its references. It may be remotely exploitable.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-34125
Severity
UNKNOWN
CVSS
N/A
EPSS
3.13%
Linux

Original NVD Description

An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlying Linux operating system. Successful exploitation enables full system compromise.