A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware Update Service. The manipulation of the argument DownloadFile results in path traversal. The attack must originate from the local network. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
References
| Link | Resource |
|---|---|
| https://tzh00203.notion.site/D-Link-DCS850L-v1-02-09-Path-Traversal-Vulnerability-in-Firmware-Update-2d8b5c52018a803abbc7e30e2858d084?source=copy_link | Exploit Third Party Advisory |
| https://vuldb.com/?ctiid.338635 | Permissions Required VDB Entry |
| https://vuldb.com/?id.338635 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.725742 | Third Party Advisory VDB Entry |
| https://www.dlink.com/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
31 Dec 2025, 22:12
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:dlink:dcs-850l:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-850l_firmware:1.02.09:*:*:*:*:*:*:* |
|
| References | () https://tzh00203.notion.site/D-Link-DCS850L-v1-02-09-Path-Traversal-Vulnerability-in-Firmware-Update-2d8b5c52018a803abbc7e30e2858d084?source=copy_link - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.338635 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.338635 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.725742 - Third Party Advisory, VDB Entry | |
| References | () https://www.dlink.com/ - Product | |
| First Time |
Dlink
Dlink dcs-850l Firmware Dlink dcs-850l |
30 Dec 2025, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-30 11:15
Updated : 2025-12-31 22:12
NVD link : CVE-2025-15245
Mitre link : CVE-2025-15245
CVE.ORG link : CVE-2025-15245
JSON object : View
Products Affected
dlink
- dcs-850l_firmware
- dcs-850l
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
