OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2025-51457

HIGH · CVSS 8.8 EPSS 1.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The D-Link DAP-2610, running firmware versions up to 2.06B08r099, is vulnerable to an authenticated command injection flaw in its web interface, specifically at the /index.xgi endpoint. This vulnerability allows an authenticated attacker to execute arbitrary system commands, potentially compromising the device's integrity and security. Organizations using this model should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-51457
Severity
HIGH
CVSS
8.8
EPSS
1.29%

Original NVD Description

D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint. An attacker with authenticated access can exploit some parameters to execute arbitrary system commands.