CVE-2025-34048

A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Nov 2025, 22:15

Type Values Removed Values Added
CWE CWE-20

17 Nov 2025, 21:15

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de path traversal en la interfaz de administración web de los routers D-Link DSL-2730U, DSL-2750U, y DSL-2750E ADSL con versiones de firmware IN_1.02, SEA_1.04 y SEA_1.07. La vulnerabilidad se debe a una validación de entrada insuficiente en el parámetro getpage del script CGI /cgi-bin/webproc. Esta falla permite a un atacante remoto no autenticado realizar ataques de path traversal mediante solicitudes manipuladas, lo que permite la lectura de archivos arbitrarios en el dispositivo afectado.
Summary (en) A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device. (en) A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.

26 Jun 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-26 16:15

Updated : 2025-11-17 22:15


NVD link : CVE-2025-34048

Mitre link : CVE-2025-34048

CVE.ORG link : CVE-2025-34048


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')