CVE-2025-14659
A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The manipulation of the argument Hostname results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
Published:Dec 14, 2025
Last Modified:Mar 8, 2026
EPS:Dec 14, 2025
EPSS Score:0.00261
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
D-link
Product
Dir-860lb1
D-link
Dir-860lb1
Vendor
D-link
Product
Dir-868lb1
D-link
Dir-868lb1
Vendor
Dlink
Product
Dir-860l B1
Dlink
Dir-860l B1
Vendor
Dlink
Product
Dir-860l B1 Firmware
Dlink
Dir-860l B1 Firmware
Vendor
Dlink
Product
Dir-868l B1
Dlink
Dir-868l B1
Vendor
Dlink
Product
Dir-868l B1 Firmware
Dlink
Dir-868l B1 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
