We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlying Linux operating system. Successful exploitation enables full system compromise.
Reserved 2025-04-15 | Published 2025-07-16 | Updated 2025-07-16 | Assigner VulnCheckCWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Peter Adkins
web.archive.org/...arnium/secpub/tree/master/D-Link/DSP-W110
raw.githubusercontent.com/...k_dspw110_cookie_noauth_exec.rb
www.vulncheck.com/...link-dspw110a1-cookie-command-injection
www.exploit-db.com/exploits/37628
Support options